<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2008-01-23T07:25:08
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhba:def:20070026" version="302" class="patch">
      <metadata>
        <title>RHBA-2007:0026: htdig bug fix update
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2007:0026-02" ref_url="https://rhn.redhat.com/errata/RHBA-2007-0026.html" />
	<description>The htdig system is a complete world wide web indexing and searching
system for a small domain or intranet. This system is not meant to replace
the need for powerful internet-wide search systems like Lycos, Infoseek,
Webcrawler and AltaVista. Instead it is meant to cover the search needs for
a single company, campus, or even a particular sub section of a web site. As
opposed to some WAIS-based or web-server based search engines, htdig can
span several web servers at a site. The type of these different web servers
doesn't matter as long as they understand the HTTP 1.0 protocol.
htdig is also used by KDE to search KDE's HTML documentation.

Bugs fixed in this update include:

* rundig script (/usr/bin/rundig) missed "$opts" on two calls to htfuzzy.

* htfuzzy segfaulted when database is empty.

* htdig was unable to open empty database on 64bits.

* htdig showed full path to configuration file when accessed from the web.

Users should upgrade to this updated package, which resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2007-06-07" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1191">CVE-2000-1191</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhba:tst:20070026002" comment="htdig is earlier than 2:3.1.6-7.el3" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070026003" comment="htdig is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhba:def:20070304" version="302" class="patch">
      <metadata>
        <title>RHBA-2007:0304: Updated kernel packages available for Red Hat Enterprise Linux 4 Update 5
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2007:0304-02" ref_url="https://rhn.redhat.com/errata/RHBA-2007-0304.html" />
	<description>New features introduced in this update include:

* Xen paravirt kernels for x86/x86_64* 
* CONFIG_SERIAL_8250_NR_UARTS is increased to 64
* implement diskdump support for sata_nv driver
* implement diskdump support for ibmvscsi driver
* add netdump support to 8139cp driver
* update CIFS to 1.45

Added Platform support:

* add support to allow disabling of MSI on PHX6700/6702 SHPC
* add support for Intel ICH9 chipset
* add PCIe power management quirk
* add support for H206 processor PowerNow! with new freqency control
* add support for AMD quad-core systems
* add support for RDTSCP
* add MCE Thresholding support for AMD 0x10 family processors
* add PCI-Express support for Altix
* add support for eClipz
* add new ppc host ethernet adapter device driver
* update SHUB2 hardware support

The following device drivers have been upgraded to new versions:

3w-9xxx: 2.26.04.010 to 2.26.05.007
ahci: 1.2 to 2.0
ata_piix: 1.05 to 2.00ac7
bnx2: 1.4.38 to 1.4.43-rh
bonding: 2.6.3 to 2.6.3-rh
cciss: 2.6.10 to 2.6.14
e1000: 7.0.33-k2-NAPI to 7.2.7-k2-NAPI
ibmvscsic: 1.5.6 to 1.5.7
ipr: 2.0.11.2 to 2.0.11.4
ixgb: 1.0.100-k2-NAPI to 1.0.109-k2-NAPI
libata: 1.20 to 2.00
megaraid_mm: 2.20.2.6 to 2.20.2.6rh
megaraid_sas: 00.00.02.03-RH1 to 00.00.03.05
mptbase: 3.02.62.01rh to 3.02.73rh
pdc_adma: 0.03 to 0.04
qla2100: 8.01.04-d7 to 8.01.04-d8-rh1
qla2200: 8.01.04-d7 to 8.01.04-d8-rh1
qla2300: 8.01.04-d7 to 8.01.04-d8-rh1
qla2322: 8.01.04-d7 to 8.01.04-d8-rh1
qla2400: 8.01.04-d7 to 8.01.04-d8-rh1
qla2xxx: 8.01.04-d7 to 8.01.04-d8-rh1
qla6312: 8.01.04-d7 to 8.01.04-d8-rh1
r8169: 1.2 to 2.2LK-NAPI
sata_mv: 0.6 to 0.7
sata_nv: 0.8 to 3.2
sata_promise: 1.04 to 1.05
sata_qstor: 0.05 to 0.06
sata_sil: 0.9 to 2.0
sata_sis: 0.5 to 0.6
sata_svw: 1.07 to 2.0
sata_sx4: 0.8 to 0.9
sata_uli: 0.5 to 1.0
sata_via: 1.1 to 2.0
sata_vsc: 1.2 to 2.0
sky2: 1.1 to 1.6
stex: 2.9.0.13 to 3.0.0.1
tg3: 3.52-rh to 3.64-rh

Infiniband update from 1.0 to OFED-1.1 code base

There were several bug fixes in various parts of the kernel. The ongoing
effort to resolve these problems has resulted in a marked improvement
in the reliability and scalability of Red Hat Enterprise Linux 4.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-04-28" />
        <updated date="2007-04-28" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2873">CVE-2005-2873</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3257">CVE-2005-3257</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-0557">CVE-2006-0557</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1863">CVE-2006-1863</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1592">CVE-2007-1592</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3379">CVE-2007-3379</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304002" comment="kernel is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304004" comment="kernel-devel is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304005" comment="kernel-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304006" comment="kernel-hugemem is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304007" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304008" comment="kernel-hugemem-devel is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304009" comment="kernel-hugemem-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304010" comment="kernel-smp is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304011" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304012" comment="kernel-smp-devel is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304013" comment="kernel-smp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304014" comment="kernel-xenU is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304015" comment="kernel-xenU is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304016" comment="kernel-xenU-devel is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304017" comment="kernel-xenU-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304018" comment="kernel-largesmp is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304019" comment="kernel-largesmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304020" comment="kernel-largesmp-devel is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304021" comment="kernel-largesmp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhba:tst:20070304022" comment="kernel-doc is earlier than 0:2.6.9-55.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304023" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhba:def:20070418" version="302" class="patch">
      <metadata>
        <title>RHBA-2007:0418: unzip bug fix update
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHBA" ref_id="RHBA-2007:0418-02" ref_url="https://rhn.redhat.com/errata/RHBA-2007-0418.html" />
	<description>The unzip utility is used to list, test, or extract files from a zip
archive. 

This update addresses the following issues:

* a TOCTOU bug that could be exploited to change file permissions (CVE-2005-2475)

* a long filename buffer overflow vulnerability (CVE-2005-4667)

All users of unzip should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-06-07" />
        <updated date="2007-06-07" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2475">CVE-2005-2475</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4667">CVE-2005-4667</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhba:tst:20070418002" comment="unzip is earlier than 0:5.50-35.EL3" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070418003" comment="unzip is signed with Red Hat master key" />
            
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070001" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0001: openoffice.org security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0001-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0001.html" />
	<description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Several integer overflow bugs were found in the OpenOffice.org WMF file
processor. An attacker could create a carefully crafted WMF file that could
cause OpenOffice.org to execute arbitrary code when the file was opened by
a victim. (CVE-2006-5870)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix for this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-03" />
        <updated date="2007-01-03" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5870">CVE-2006-5870</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001002" comment="openoffice.org is earlier than 0:1.1.2-35.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001004" comment="openoffice.org-i18n is earlier than 0:1.1.2-35.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-i18n is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001006" comment="openoffice.org-libs is earlier than 0:1.1.2-35.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001009" comment="openoffice.org is earlier than 0:1.1.5-6.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001010" comment="openoffice.org-i18n is earlier than 0:1.1.5-6.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-i18n is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001011" comment="openoffice.org-kde is earlier than 0:1.1.5-6.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001012" comment="openoffice.org-kde is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001013" comment="openoffice.org-libs is earlier than 0:1.1.5-6.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070002" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0002: XFree86 security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0002-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0002.html" />
	<description>XFree86 is an implementation of the X Window System, which provides the
core functionality for the Linux graphical desktop.

iDefense reported three integer overflow flaws in the XFree86 Render and
DBE extensions. A malicious authorized client could exploit this issue to
cause a denial of service (crash) or potentially execute arbitrary code
with root privileges on the XFree86 server. (CVE-2006-6101, CVE-2006-6102,
CVE-2006-6103)

Users of XFree86 should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-10" />
        <updated date="2007-01-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6101">CVE-2006-6101</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6102">CVE-2006-6102</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6103">CVE-2006-6103</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002002" comment="XFree86 is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002003" comment="XFree86 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002004" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002005" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002006" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002007" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002008" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002009" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002010" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002011" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002012" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002013" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002014" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002015" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002016" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002017" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002018" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002019" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002020" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002021" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002022" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002023" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002024" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002025" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002026" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002027" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002028" comment="XFree86-Xnest is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002029" comment="XFree86-Xnest is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002030" comment="XFree86-Xvfb is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002031" comment="XFree86-Xvfb is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002032" comment="XFree86-base-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002033" comment="XFree86-base-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002034" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002035" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002036" comment="XFree86-devel is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002037" comment="XFree86-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002038" comment="XFree86-doc is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002039" comment="XFree86-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002040" comment="XFree86-font-utils is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002041" comment="XFree86-font-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002042" comment="XFree86-libs is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002043" comment="XFree86-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002044" comment="XFree86-libs-data is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002045" comment="XFree86-libs-data is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002046" comment="XFree86-sdk is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002047" comment="XFree86-sdk is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002048" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002049" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002050" comment="XFree86-tools is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002051" comment="XFree86-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002052" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002053" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002054" comment="XFree86-twm is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002055" comment="XFree86-twm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002056" comment="XFree86-xauth is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002057" comment="XFree86-xauth is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002058" comment="XFree86-xdm is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002059" comment="XFree86-xdm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002060" comment="XFree86-xfs is earlier than 0:4.3.0-115.EL" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070002061" comment="XFree86-xfs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070003" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0003: xorg-x11 security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0003-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0003.html" />
	<description>X.org is an open source implementation of the X Window System. It provides
the basic low-level functionality that full-fledged graphical user
interfaces are designed upon.

iDefense reported three integer overflow flaws in the X.org Render and DBE
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or potentially execute arbitrary code with root
privileges on the X.org server. (CVE-2006-6101, CVE-2006-6102, CVE-2006-6103)

Users of X.org should upgrade to these updated packages, which contain a
backported patch and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-10" />
        <updated date="2007-01-10" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6101">CVE-2006-6101</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6102">CVE-2006-6102</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6103">CVE-2006-6103</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003003" comment="xorg-x11 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003004" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003005" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003006" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003007" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003008" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003009" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003010" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003011" comment="xorg-x11-Xnest is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003012" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003013" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003014" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003015" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003016" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003017" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003018" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003019" comment="xorg-x11-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003020" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003021" comment="xorg-x11-doc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003022" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003023" comment="xorg-x11-font-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003024" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003025" comment="xorg-x11-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003026" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003027" comment="xorg-x11-sdk is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003028" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003029" comment="xorg-x11-tools is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003030" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003031" comment="xorg-x11-twm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003032" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003033" comment="xorg-x11-xauth is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003034" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003035" comment="xorg-x11-xdm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003036" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.13.37.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070003037" comment="xorg-x11-xfs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070008" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0008: dbus security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0008-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0008.html" />
	<description>D-BUS is a system for sending messages between applications. It is used
both for the systemwide message bus service, and as a
per-user-login-session messaging facility.

Kimmo Hämäläinen discovered a flaw in the way D-BUS processes certain
messages. It is possible for a local unprivileged D-BUS process to disrupt
the ability of another D-BUS process to receive messages. (CVE-2006-6107)

Users of dbus are advised to upgrade to these updated packages, which
contain backported patches to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-08" />
        <updated date="2007-02-08" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6107">CVE-2006-6107</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008002" comment="dbus is earlier than 0:0.22-12.EL.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008003" comment="dbus is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008004" comment="dbus-devel is earlier than 0:0.22-12.EL.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008005" comment="dbus-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008006" comment="dbus-glib is earlier than 0:0.22-12.EL.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008007" comment="dbus-glib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008008" comment="dbus-python is earlier than 0:0.22-12.EL.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008009" comment="dbus-python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008010" comment="dbus-x11 is earlier than 0:0.22-12.EL.8" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070008011" comment="dbus-x11 is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070009" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0009: flash-plugin security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux Extras 3</platform>
        <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0009-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0009.html" />
	<description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
browser plug-in.

A flaw was found in the way the Adobe Flash Player generates HTTP requests.
It was possible for a malicious Adobe Flash file to modify the HTTP header
of the client request, which could be leveraged to exploit certain HTTP proxy
and web server flaws. (CVE-2006-5330)

Users of Adobe Flash Player should upgrade to this updated package, which
contains version 7.0.69 and is not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-09" />
        <updated date="2007-01-09" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5330">CVE-2006-5330</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:rhel_extras:3</cpe>
        <cpe>cpe://redhat:rhel_extras:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux Extras 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070009002" comment="flash-plugin is earlier than 0:7.0.69-1.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070009003" comment="flash-plugin is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux Extras 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070009005" comment="flash-plugin is earlier than 0:7.0.69-1.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070009003" comment="flash-plugin is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070011" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0011: libgsf security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0011-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0011.html" />
	<description>The GNOME Structured File Library is a utility library for reading and
writing structured file formats.

A heap based buffer overflow flaw was found in the way GNOME Structured
File Library processes and certain OLE documents. If an person opened a
specially crafted OLE file, it could cause the client application to crash or
execute arbitrary code. (CVE-2006-4514)

Users of GNOME Structured File Library should upgrade to these updated
packages, which contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-11" />
        <updated date="2007-01-11" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4514">CVE-2006-4514</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011002" comment="libgsf is earlier than 0:1.6.0-7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011003" comment="libgsf is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011004" comment="libgsf-devel is earlier than 0:1.6.0-7" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011005" comment="libgsf-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011007" comment="libgsf is earlier than 0:1.10.1-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011003" comment="libgsf is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011008" comment="libgsf-devel is earlier than 0:1.10.1-2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070011005" comment="libgsf-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070014" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0014: kernel security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0014-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0014.html" />
	<description>The Linux kernel handles the basic functions of the operating system.

These new kernel packages contain fixes for the security issues described
below: 

* a flaw in the get_fdb_entries function of the network bridging support
that allowed a local user to cause a denial of service (crash) or allow a
potential privilege escalation (CVE-2006-5751, Important)

* an information leak in the _block_prepare_write function that allowed a
local user to read kernel memory (CVE-2006-4813, Important)

* an information leak in the copy_from_user() implementation on s390 and
s390x platforms that allowed a local user to read kernel memory
(CVE-2006-5174, Important)

* a flaw in the handling of /proc/net/ip6_flowlabel that allowed a local
user to cause a denial of service (infinite loop) (CVE-2006-5619, Important)

* a flaw in the AIO handling that allowed a local user to cause a denial of
 service (panic) (CVE-2006-5754, Important)

* a race condition in the mincore system core that allowed a local user to
cause a denial of service (system hang) (CVE-2006-4814, Moderate)

* a flaw in the ELF handling on ia64 and sparc architectures which
triggered a cross-region memory mapping and allowed a local user to cause a
denial of service (CVE-2006-4538, Moderate)

* a flaw in the dev_queue_xmit function of the network subsystem that
allowed a local user to cause a denial of service (data corruption)
(CVE-2006-6535, Moderate)

* a flaw in the handling of CAPI messages over Bluetooth that allowed a
remote system to cause a denial of service or potential code execution.
This flaw is only exploitable if a privileged user establishes a connection
to a malicious remote device (CVE-2006-6106, Moderate)

* a flaw in the listxattr system call that allowed a local user to cause a
denial of service (data corruption) or potential privilege escalation. To
successfully exploit this flaw the existence of a bad inode is required
first (CVE-2006-5753, Moderate)

* a flaw in the __find_get_block_slow function that allowed a local
privileged user to cause a denial of service (CVE-2006-5757, Low)

* various flaws in the supported filesystems that allowed a local
privileged user to cause a denial of service (CVE-2006-5823, CVE-2006-6053,
CVE-2006-6054, CVE-2006-6056, Low)

In addition to the security issues described above, fixes for the following
bugs were included:

* initialization error of the tg3 driver with some BCM5703x network card

* a memory leak in the audit subsystem

* x86_64 nmi watchdog timeout is too short

* ext2/3 directory reads fail intermittently

Red Hat would like to thank Dmitriy Monakhov and Kostantin Khorenko for
reporting issues fixed in this erratum.

All Red Hat Enterprise Linux 4 users are advised to upgrade their kernels
to the packages associated with their machine architecture and
configurations as listed in this erratum.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-30" />
        <updated date="2007-01-30" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4538">CVE-2006-4538</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4813">CVE-2006-4813</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4814">CVE-2006-4814</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5174">CVE-2006-5174</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5619">CVE-2006-5619</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5751">CVE-2006-5751</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5753">CVE-2006-5753</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5754">CVE-2006-5754</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5757">CVE-2006-5757</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5823">CVE-2006-5823</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6053">CVE-2006-6053</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6054">CVE-2006-6054</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6056">CVE-2006-6056</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6106">CVE-2006-6106</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6535">CVE-2006-6535</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014002" comment="kernel is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304003" comment="kernel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014004" comment="kernel-devel is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304005" comment="kernel-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014006" comment="kernel-hugemem is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304007" comment="kernel-hugemem is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014008" comment="kernel-hugemem-devel is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304009" comment="kernel-hugemem-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014010" comment="kernel-smp is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304011" comment="kernel-smp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014012" comment="kernel-smp-devel is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304013" comment="kernel-smp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014014" comment="kernel-largesmp is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304019" comment="kernel-largesmp is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304021" comment="kernel-largesmp-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070014018" comment="kernel-doc is earlier than 0:2.6.9-42.0.8.EL" />
            <criterion test_ref="oval:com.redhat.rhba:tst:20070304023" comment="kernel-doc is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070015" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0015: ImageMagick security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0015-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0015.html" />
	<description>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Several security flaws were discovered in the way ImageMagick decodes DCM,
PALM, and SGI graphic files.  An attacker may be able to execute arbitrary
code on a victim's machine if they were able to trick the victim into
opening a specially crafted image file (CVE-2006-5456, CVE-2006-5868).

A heap overflow flaw was found in ImageMagick.  An attacker may be able to
execute arbitrary code on a victim's machine if they were able to trick the
victim into opening a specially crafted file (CVE-2006-2440).  This issue
only affected the version of ImageMagick distributed with Red Hat
Enterprise Linux 4.

Users of ImageMagick should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-15" />
        <updated date="2007-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2440">CVE-2006-2440</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5456">CVE-2006-5456</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5868">CVE-2006-5868</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015002" comment="ImageMagick is earlier than 0:5.5.6-24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015004" comment="ImageMagick-c++ is earlier than 0:5.5.6-24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015006" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015008" comment="ImageMagick-devel is earlier than 0:5.5.6-24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015010" comment="ImageMagick-perl is earlier than 0:5.5.6-24" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015013" comment="ImageMagick is earlier than 0:6.0.7.1-16.0.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015003" comment="ImageMagick is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015014" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-16.0.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015005" comment="ImageMagick-c++ is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015015" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-16.0.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015007" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015016" comment="ImageMagick-devel is earlier than 0:6.0.7.1-16.0.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015009" comment="ImageMagick-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015017" comment="ImageMagick-perl is earlier than 0:6.0.7.1-16.0.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070015011" comment="ImageMagick-perl is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070017" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0017: Adobe Acrobat Reader security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0017-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0017.html" />
	<description>The Adobe Acrobat Reader allows users to view and print documents in
portable document format (PDF).

A cross site scripting flaw was found in the way the Adobe Reader Plugin
processes certain malformed URLs. A malicious web page could inject
arbitrary javascript into the browser session which could possibly lead to
a cross site scripting attack. (CVE-2007-0045)

Two arbitrary code execution flaws were found in the way Adobe Reader
processes malformed document files. It may be possible to execute arbitrary
code on a victim's machine if the victim opens a malicious PDF file.
(CVE-2006-5857, CVE-2007-0046)

All users of Acrobat Reader are advised to upgrade to these updated
packages, which contain Acrobat Reader version 7.0.9 and are not vulnerable
to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-11" />
        <updated date="2007-01-11" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5857">CVE-2006-5857</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045">CVE-2007-0045</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0046">CVE-2007-0046</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:rhel_extras:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux Extras 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070017002" comment="acroread is earlier than 0:7.0.9-1.2.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070017003" comment="acroread is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070017004" comment="acroread-plugin is earlier than 0:7.0.9-1.2.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070017005" comment="acroread-plugin is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070018" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0018: fetchmail security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0018-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0018.html" />
	<description>Fetchmail is a remote mail retrieval and forwarding utility.

A denial of service flaw was found when Fetchmail was run in multidrop
mode.  A malicious mail server could send a message without headers which
would cause Fetchmail to crash (CVE-2005-4348).  This issue did not affect
the version of Fetchmail shipped with Red Hat Enterprise Linux 2.1 or 3.

A flaw was found in the way Fetchmail used TLS encryption to connect to
remote hosts.  Fetchmail provided no way to enforce the use of TLS
encryption and would not authenticate POP3 protocol connections properly
(CVE-2006-5867).  This update corrects this issue by enforcing TLS
encryption when the "sslproto" configuration directive is set to "tls1".  

Users of Fetchmail should update to these packages, which contain 
backported patches to correct these issues.

Note: This update may break configurations which assumed that Fetchmail
would use plain-text authentication if TLS encryption is not supported by
the POP3 server even if the "sslproto" directive is set to "tls1".  If you
are using a custom configuration that depended on this behavior you will
need to modify your configuration appropriately after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-31" />
        <updated date="2007-01-31" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4348">CVE-2005-4348</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5867">CVE-2006-5867</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070018002" comment="fetchmail is earlier than 0:6.2.0-3.el3.3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070018003" comment="fetchmail is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070018005" comment="fetchmail is earlier than 0:6.2.5-6.el4.5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070018003" comment="fetchmail is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070019" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0019: gtk2 security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0019-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0019.html" />
	<description>The gtk2 package contains the GIMP ToolKit (GTK+), a library for creating
graphical user interfaces for the X Window System.

A bug was found in the way the gtk2 GdkPixbufLoader() function processed
invalid input.   Applications linked against gtk2 could crash if they
loaded a malformed image file. (CVE-2007-0010)

Users of gtk2 are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-24" />
        <updated date="2007-01-24" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0010">CVE-2007-0010</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070019002" comment="gtk2 is earlier than 0:2.4.13-22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070019003" comment="gtk2 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070019004" comment="gtk2-devel is earlier than 0:2.4.13-22" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070019005" comment="gtk2-devel is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070021" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0021: Adobe Acrobat Reader security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux Extras 3</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0021-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0021.html" />
	<description>The Adobe Reader allows users to view and print documents in portable
document format (PDF).

A cross site scripting flaw was found in the way the Adobe Reader Plugin
processes certain malformed URLs. A malicious web page could inject
arbitrary javascript into the browser session which could possibly lead to
a cross site scripting attack. (CVE-2007-0045)

Two arbitrary code execution flaws were found in the way Adobe Reader
processes malformed document files. It may be possible to execute arbitrary
code on a victim's machine if the victim opens a malicious PDF file.
(CVE-2006-5857, CVE-2007-0046)

Please note that Adobe Reader 7.0.9 requires versions of several system
libraries that were not shipped with Red Hat Enterprise Linux 3.  This
update contains additional packages that provide the required system
library versions for Adobe Reader.  These additional packages are only
required by Adobe Reader and do not replace or affect any other aspects of
a Red Hat Enterprise Linux 3 system.

All users of Adobe Reader are advised to upgrade to these updated packages,
which contain Adobe Reader version 7.0.9 and additional libraries to
correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-22" />
        <updated date="2007-01-23" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5857">CVE-2006-5857</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0045">CVE-2007-0045</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0046">CVE-2007-0046</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:rhel_extras:3</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux Extras 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021002" comment="acroread-libs-atk is earlier than 0:1.8.0-1.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021003" comment="acroread-libs-atk is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021004" comment="acroread-libs-glib2 is earlier than 0:2.4.7-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021005" comment="acroread-libs-glib2 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021006" comment="acroread-libs-gtk2 is earlier than 0:2.4.13-1.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021007" comment="acroread-libs-gtk2 is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021008" comment="acroread-libs-gtk2-engines is earlier than 0:2.2.0-1.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021009" comment="acroread-libs-gtk2-engines is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021010" comment="acroread-libs-pango is earlier than 0:1.6.0-1.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021011" comment="acroread-libs-pango is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021012" comment="acroread is earlier than 0:7.0.9-1.1.1.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070017003" comment="acroread is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070021014" comment="acroread-plugin is earlier than 0:7.0.9-1.1.1.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070017005" comment="acroread-plugin is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070022" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0022: squirrelmail security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0022-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0022.html" />
	<description>SquirrelMail is a standards-based webmail package written in PHP.

Several cross-site scripting bugs were discovered in SquirrelMail.  An
attacker could inject arbitrary Javascript or HTML content into
SquirrelMail pages by tricking a user into visiting a carefully crafted
URL.  (CVE-2006-6142) 

Users of SquirrelMail should upgrade to this erratum package, which
contains a backported patch to correct these issues. 

Notes:
- After installing this update, users are advised to restart their
httpd service to ensure that the updated version functions correctly.
- config.php should NOT be modified, please modify config_local.php instead.
- Known Bug: The configuration generator may potentially produce bad
options that interfere with the operation of this application.  Applying
specific config changes to config_local.php manually is recommended.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-01-31" />
        <updated date="2007-01-31" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6142">CVE-2006-6142</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070022002" comment="squirrelmail is earlier than 0:1.4.8-4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070022003" comment="squirrelmail is signed with Red Hat master key" />
            
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
            

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070022005" comment="squirrelmail is earlier than 0:1.4.8-4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070022003" comment="squirrelmail is signed with Red Hat master key" />
            
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070033" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0033: openoffice.org security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0033-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0033.html" />
	<description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

iDefense reported an integer overflow flaw in libwpd, a library used
internally to OpenOffice.org for handling Word Perfect documents.  An
attacker could create a carefully crafted Word Perfect file that could
cause OpenOffice.org to crash or possibly execute arbitrary code if the
file was opened by a victim. (CVE-2007-1466)

John Heasman discovered a stack overflow in the StarCalc parser in
OpenOffice.org.  An attacker could create a carefully crafted StarCalc file
that could cause OpenOffice.org to crash or possibly execute arbitrary code
if the file was opened by a victim. (CVE-2007-0238)

Flaws were discovered in the way OpenOffice.org handled hyperlinks.  An
attacker could create an OpenOffice.org document which could run commands
if a victim opened the file and clicked on a malicious hyperlink. 
(CVE-2007-0239)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes for these issues.

Red Hat would like to thank Fridrich Štrba for alerting us to the issue
CVE-2007-1466 and providing a patch, and John Heasman for
CVE-2007-0238.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-22" />
        <updated date="2007-03-22" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0238">CVE-2007-0238</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0239">CVE-2007-0239</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1466">CVE-2007-1466</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033002" comment="openoffice.org is earlier than 0:1.1.2-38.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033004" comment="openoffice.org-i18n is earlier than 0:1.1.2-38.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-i18n is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033006" comment="openoffice.org-libs is earlier than 0:1.1.2-38.2.0.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033009" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001003" comment="openoffice.org is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033010" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001005" comment="openoffice.org-i18n is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033011" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001012" comment="openoffice.org-kde is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070033013" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070001007" comment="openoffice.org-libs is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070044" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0044: bind security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0044-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0044.html" />
	<description>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.  

A flaw was found in the way BIND processed certain DNS query responses.  On
servers that had enabled DNSSEC validation, this could allow an remote
attacker to cause a denial of service.  (CVE-2007-0494)

For users of Red Hat Enterprise Linux 3, the previous BIND update caused an
incompatible change to the default configuration that resulted in rndc not
sharing the key with the named daemon. This update corrects this bug and
restores the behavior prior to that update.

Updating the bind package in Red Hat Enterprise Linux 3 could result in
nonfunctional configuration in case the bind-libs package was not updated.
This update corrects this bug by adding the correct dependency on bind-libs.

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-06" />
        <updated date="2007-02-06" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0494">CVE-2007-0494</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044002" comment="bind is earlier than 20:9.2.4-20.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044003" comment="bind is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044004" comment="bind-chroot is earlier than 20:9.2.4-20.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044005" comment="bind-chroot is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044006" comment="bind-devel is earlier than 20:9.2.4-20.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044007" comment="bind-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044008" comment="bind-libs is earlier than 20:9.2.4-20.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044009" comment="bind-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044010" comment="bind-utils is earlier than 20:9.2.4-20.EL3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044011" comment="bind-utils is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044013" comment="bind is earlier than 20:9.2.4-24.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044003" comment="bind is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044014" comment="bind-chroot is earlier than 20:9.2.4-24.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044005" comment="bind-chroot is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044015" comment="bind-devel is earlier than 20:9.2.4-24.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044007" comment="bind-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044016" comment="bind-libs is earlier than 20:9.2.4-24.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044009" comment="bind-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044017" comment="bind-utils is earlier than 20:9.2.4-24.EL4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070044011" comment="bind-utils is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070055" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0055: libwpd security update
        (Important)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0055-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0055.html" />
	<description>libwpd is a library for reading and converting Word Perfect documents.

iDefense reported several overflow bugs in libwpd.  An attacker could
create a carefully crafted Word Perfect file that could cause an
application linked with libwpd, such as OpenOffice, to crash or possibly
execute arbitrary code if the file was opened by a victim. (CVE-2007-0002)

All users are advised to upgrade to these updated packages, which contain a
backported fix for this issue.

Red Hat would like to thank Fridrich Štrba for alerting us to these issues
and providing a patch.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Important</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-16" />
        <updated date="2007-03-16" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0002">CVE-2007-0002</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1466">CVE-2007-1466</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:5</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070055002" comment="libwpd is earlier than 0:0.8.7-3.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070055003" comment="libwpd is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070055004" comment="libwpd-tools is earlier than 0:0.8.7-3.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070055005" comment="libwpd-tools is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070055006" comment="libwpd-devel is earlier than 0:0.8.7-3.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070055007" comment="libwpd-devel is signed with Red Hat redhatrelease key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070057" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0057: bind security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0057-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0057.html" />
	<description>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.  

A flaw was found in the way BIND processed certain DNS query responses. On
servers that had enabled DNSSEC validation, this could allow a remote
attacker to cause a denial of service. (CVE-2007-0494)

A use-after-free flaw was found in BIND. On servers that have recursion
enabled, this could allow a remote attacker to cause a denial of service. 
(CVE-2007-0493)

Users of BIND are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0493">CVE-2007-0493</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0494">CVE-2007-0494</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:5</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057002" comment="bind is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057003" comment="bind is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057004" comment="bind-libs is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057005" comment="bind-libs is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057006" comment="bind-sdb is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057007" comment="bind-sdb is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057008" comment="bind-utils is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057009" comment="bind-utils is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057010" comment="bind-chroot is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057011" comment="bind-chroot is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057012" comment="bind-devel is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057013" comment="bind-devel is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057014" comment="bind-libbind-devel is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057015" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057016" comment="caching-nameserver is earlier than 30:9.3.3-8.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070057017" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070060" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0060: samba security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0060-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0060.html" />
	<description>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service flaw was found in Samba's smbd daemon process. An
authenticated user could send a specially crafted request which would cause
a smbd child process to enter an infinite loop condition. By opening
multiple CIFS sessions, an attacker could exhaust system resources.
(CVE-2007-0452)

Users of Samba should update to these packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-15" />
        <updated date="2007-02-15" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452">CVE-2007-0452</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060002" comment="samba is earlier than 0:3.0.9-1.3E.12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060004" comment="samba-client is earlier than 0:3.0.9-1.3E.12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-client is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060006" comment="samba-common is earlier than 0:3.0.9-1.3E.12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060008" comment="samba-swat is earlier than 0:3.0.9-1.3E.12" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-swat is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060011" comment="samba is earlier than 0:3.0.10-1.4E.11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060003" comment="samba is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060012" comment="samba-client is earlier than 0:3.0.10-1.4E.11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060005" comment="samba-client is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060013" comment="samba-common is earlier than 0:3.0.10-1.4E.11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060007" comment="samba-common is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060014" comment="samba-swat is earlier than 0:3.0.10-1.4E.11" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070060009" comment="samba-swat is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070061" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0061: samba security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0061-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0061.html" />
	<description>Samba provides file and printer sharing services to SMB/CIFS clients.

A denial of service flaw was found in Samba's smbd daemon process. An
authenticated user could send a specially crafted request which would cause
a smbd child process to enter an infinite loop condition. By opening
multiple CIFS sessions, an attacker could exhaust system resources
(CVE-2007-0452).

Users of Samba should update to these packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0452">CVE-2007-0452</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:5</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061002" comment="samba is earlier than 0:3.0.23c-2.el5.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061003" comment="samba is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061004" comment="samba-client is earlier than 0:3.0.23c-2.el5.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061005" comment="samba-client is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061006" comment="samba-common is earlier than 0:3.0.23c-2.el5.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061007" comment="samba-common is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061008" comment="samba-swat is earlier than 0:3.0.23c-2.el5.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070061009" comment="samba-swat is signed with Red Hat redhatrelease key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070062" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0062: java-1.4.2-ibm security update
        (Critical)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux Extras 3</platform>
        <platform>Red Hat Enterprise Linux Extras 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0062-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0062.html" />
	<description>IBM's 1.4.2 SR7 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

A number of security issues were found:

Vulnerabilities were discovered in the Java Runtime Environment.   An
untrusted applet could use these vulnerabilities to access data from other
applets. (CVE-2006-6736, CVE-2006-6737)

Serialization flaws were discovered in the Java Runtime Environment.  An
untrusted applet or application could use these flaws to elevate its
privileges.  (CVE-2006-6745)

Buffer overflow vulnerabilities were discovered in the Java Runtime
Environment.  An untrusted applet could use these flaws to elevate its
privileges, possibly reading and writing local files or executing local
applications.  (CVE-2006-6731)

Daniel Bleichenbacher discovered an attack on PKCS #1 v1.5 signatures.
Where an RSA key with exponent 3 is used it may be possible for an attacker
to forge a PKCS #1 v1.5 signature that would be incorrectly verified by
implementations that do not check for excess data in the RSA exponentiation
result of the signature.  (CVE-2006-4339)

All users of java-1.4.2-ibm should upgrade to these updated packages, which
contain IBM's 1.4.2 SR7 Java release which resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Critical</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-07" />
        <updated date="2007-02-07" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4339">CVE-2006-4339</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6731">CVE-2006-6731</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6736">CVE-2006-6736</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6737">CVE-2006-6737</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6745">CVE-2006-6745</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:rhel_extras:3</cpe>
        <cpe>cpe://redhat:rhel_extras:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux Extras 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.7-1jpp.4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062003" comment="java-1.4.2-ibm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062004" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.7-1jpp.4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062005" comment="java-1.4.2-ibm-demo is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062006" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.7-1jpp.4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062007" comment="java-1.4.2-ibm-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062008" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.7-1jpp.4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062009" comment="java-1.4.2-ibm-jdbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062010" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.7-1jpp.4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062011" comment="java-1.4.2-ibm-plugin is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062012" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.7-1jpp.4.el3" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062013" comment="java-1.4.2-ibm-src is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux Extras 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062015" comment="java-1.4.2-ibm is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062003" comment="java-1.4.2-ibm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062016" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062005" comment="java-1.4.2-ibm-demo is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062017" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062007" comment="java-1.4.2-ibm-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062018" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062019" comment="java-1.4.2-ibm-javacomm is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062020" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062009" comment="java-1.4.2-ibm-jdbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062021" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062011" comment="java-1.4.2-ibm-plugin is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062022" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.7-1jpp.4.el4" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070062013" comment="java-1.4.2-ibm-src is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070064" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0064: postgresql security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0064-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0064.html" />
	<description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

A flaw was found in the way the PostgreSQL server handles certain
SQL-language functions. An authenticated user could execute a sequence of
commands which could crash the PostgreSQL server or possibly read from
arbitrary memory locations. A user would need to have permissions to drop
and add database tables to be able to exploit this issue (CVE-2007-0555).

A denial of service flaw was found affecting the PostgreSQL server running
on Red Hat Enterprise Linux 4 systems. An authenticated user could execute
an SQL command which could crash the PostgreSQL server. (CVE-2006-5540)

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 7.4.16 or 7.3.18, which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-02-07" />
        <updated date="2007-02-07" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5540">CVE-2006-5540</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555">CVE-2007-0555</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064002" comment="rh-postgresql is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064003" comment="rh-postgresql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064004" comment="rh-postgresql-contrib is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064005" comment="rh-postgresql-contrib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064006" comment="rh-postgresql-devel is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064007" comment="rh-postgresql-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064008" comment="rh-postgresql-docs is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064009" comment="rh-postgresql-docs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064010" comment="rh-postgresql-jdbc is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064011" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064012" comment="rh-postgresql-libs is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064013" comment="rh-postgresql-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064014" comment="rh-postgresql-pl is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064015" comment="rh-postgresql-pl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064016" comment="rh-postgresql-python is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064017" comment="rh-postgresql-python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064018" comment="rh-postgresql-server is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064019" comment="rh-postgresql-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064020" comment="rh-postgresql-tcl is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064021" comment="rh-postgresql-tcl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064022" comment="rh-postgresql-test is earlier than 0:7.3.18-1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064023" comment="rh-postgresql-test is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064025" comment="postgresql is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064026" comment="postgresql is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064027" comment="postgresql-contrib is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064028" comment="postgresql-contrib is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064029" comment="postgresql-devel is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064030" comment="postgresql-devel is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064031" comment="postgresql-docs is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064032" comment="postgresql-docs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064033" comment="postgresql-jdbc is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064034" comment="postgresql-jdbc is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064035" comment="postgresql-libs is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064036" comment="postgresql-libs is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064037" comment="postgresql-pl is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064038" comment="postgresql-pl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064039" comment="postgresql-python is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064040" comment="postgresql-python is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064041" comment="postgresql-server is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064042" comment="postgresql-server is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064043" comment="postgresql-tcl is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064044" comment="postgresql-tcl is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064045" comment="postgresql-test is earlier than 0:7.4.16-1.RHEL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070064046" comment="postgresql-test is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070065" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0065: bluez-utils security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 4</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0065-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0065.html" />
	<description>The bluez-utils package contains Bluetooth daemons and utilities.

A flaw was found in the Bluetooth HID daemon (hidd). A remote attacker
would have been able to inject keyboard and mouse events via a Bluetooth
connection without any authorization. (CVE-2006-6899)

Note that Red Hat Enterprise Linux does not come with the Bluetooth HID
daemon enabled by default.

Users of bluez-utils are advised to upgrade to these updated packages, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-05-14" />
        <updated date="2007-05-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6899">CVE-2006-6899</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070065002" comment="bluez-utils is earlier than 0:2.10-2.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070065003" comment="bluez-utils is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070065004" comment="bluez-utils-cups is earlier than 0:2.10-2.2" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070065005" comment="bluez-utils-cups is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070066" version="302" class="patch">
      <metadata>
        <title>RHSA-2007:0066: wireshark security update
        (Low)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 3</platform>
        <platform>Red Hat Enterprise Linux 4</platform>
        <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0066-02" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0066.html" />
	<description>Wireshark is a program for monitoring network traffic.

Several denial of service bugs were found in Wireshark's LLT, IEEE 802.11,
http, and tcp protocol dissectors. It was possible for Wireshark to crash
or stop responding if it read a malformed packet off the network.
(CVE-2007-0456, CVE-2007-0457, CVE-2007-0458, CVE-2007-0459)

Users of Wireshark should upgrade to these updated packages containing
Wireshark version 0.99.5, which is not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Low</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0456">CVE-2007-0456</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0457">CVE-2007-0457</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0458">CVE-2007-0458</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0459">CVE-2007-0459</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:3</cpe>
        <cpe>cpe://redhat:enterprise_linux:4</cpe>
        <cpe>cpe://redhat:enterprise_linux:5</cpe>
        </affected_cpe_list>
</advisory>
      </metadata><criteria operator="OR">
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070026001" comment="Red Hat Enterprise Linux 3 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066002" comment="wireshark is earlier than 0:0.99.5-EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066003" comment="wireshark is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066004" comment="wireshark-gnome is earlier than 0:0.99.5-EL3.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066005" comment="wireshark-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhba:tst:20070304001" comment="Red Hat Enterprise Linux 4 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066007" comment="wireshark is earlier than 0:0.99.5-EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066003" comment="wireshark is signed with Red Hat master key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066008" comment="wireshark-gnome is earlier than 0:0.99.5-EL4.1" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066005" comment="wireshark-gnome is signed with Red Hat master key" />
            </criteria>
    </criteria>
  </criteria>
  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066010" comment="wireshark is earlier than 0:0.99.5-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066011" comment="wireshark is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066012" comment="wireshark-gnome is earlier than 0:0.99.5-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070066013" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
            </criteria>
    </criteria>
  </criteria>
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20070068" version="303" class="patch">
      <metadata>
        <title>RHSA-2007:0068: postgresql security update
        (Moderate)
	</title>
  	<affected family="unix">
        <platform>Red Hat Enterprise Linux 5</platform>
        </affected>
        <reference source="RHSA" ref_id="RHSA-2007:0068-03" ref_url="https://rhn.redhat.com/errata/RHSA-2007-0068.html" />
	<description>PostgreSQL is an advanced Object-Relational database management system
(DBMS).

Two flaws were found in the way the PostgreSQL server handles certain
SQL-language functions. An authenticated user could execute a sequence of
commands which could crash the PostgreSQL server or possibly read from
arbitrary memory locations. A user would need to have permissions to drop
and add database tables to be able to exploit these issues (CVE-2007-0555,
CVE-2007-0556).

Several denial of service flaws were found in the PostgreSQL server.  An
authenticated user could execute certain SQL commands which could crash the
PostgreSQL server (CVE-2006-5540, CVE-2006-5541, CVE-2006-5542).

Users of PostgreSQL should upgrade to these updated packages containing
PostgreSQL version 8.1.8 which corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">
        <severity>Moderate</severity>
        <rights>Copyright 2007 Red Hat, Inc.</rights>
        <issued date="2007-03-14" />
        <updated date="2007-03-14" />
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5540">CVE-2006-5540</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5541">CVE-2006-5541</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5542">CVE-2006-5542</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0555">CVE-2007-0555</cve>
        <cve href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0556">CVE-2007-0556</cve>
  	<affected_cpe_list>
        <cpe>cpe://redhat:enterprise_linux:5</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>  <criteria operator="AND">
    <criterion test_ref="oval:com.redhat.rhsa:tst:20070055001" comment="Red Hat Enterprise Linux 5 is installed" />
    <criteria operator="OR">
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068002" comment="postgresql is earlier than 0:8.1.8-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068003" comment="postgresql is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068004" comment="postgresql-contrib is earlier than 0:8.1.8-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068005" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068006" comment="postgresql-docs is earlier than 0:8.1.8-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068007" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068008" comment="postgresql-libs is earlier than 0:8.1.8-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068009" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068010" comment="postgresql-python is earlier than 0:8.1.8-1.el5" />
            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068011" comment="postgresql-python is signed with Red Hat redhatrelease key" />
            </criteria>
            <criteria operator="AND">

            <criterion test_ref="oval:com.redhat.rhsa:tst:20070068012" comment="postgresql-tcl is earlier than 0:8.1.8-1.el5" />
            <criterion test_ref="oval:com.red