<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-09-30T09:52:52
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20080002" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0002: tog-pegasus security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0002.html" />
          <reference source="CVE" ref_id="CVE-2008-0003" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0003.html" />
    
    <description>The tog-pegasus packages provide OpenPegasus Web-Based Enterprise
Management (WBEM) services. WBEM is a platform and resource independent
DMTF standard that defines a common information model, and communication
protocol for monitoring and controlling resources.

During a security audit, a stack buffer overflow flaw was found in the PAM
authentication code in the OpenPegasus CIM management server. An
unauthenticated remote user could trigger this flaw and potentially execute
arbitrary code with root privileges. (CVE-2008-0003)

Note that the tog-pegasus packages are not installed by default on Red Hat
Enterprise Linux. The Red Hat Security Response Team believes that it would
be hard to remotely exploit this issue to execute arbitrary code, due to
the default SELinux targeted policy on Red Hat Enterprise Linux 4 and 5,
and the SELinux memory protection tests enabled by default on Red Hat
Enterprise Linux 5.

Users of tog-pegasus should upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
updated packages the tog-pegasus service should be restarted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-07" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0003.html">CVE-2008-0003</cve>
                <bugzilla href="http://bugzilla.redhat.com/426578" id="426578">CVE-2008-0003 tog-pegasus pam authentication buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002002" comment="tog-pegasus is earlier than 2:2.6.1-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002003" comment="tog-pegasus is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002004" comment="tog-pegasus-devel is earlier than 2:2.6.1-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002005" comment="tog-pegasus-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002007" comment="tog-pegasus is earlier than 2:2.5.1-5.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002008" comment="tog-pegasus is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002009" comment="tog-pegasus-test is earlier than 2:2.5.1-5.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002010" comment="tog-pegasus-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002011" comment="tog-pegasus-devel is earlier than 2:2.5.1-5.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002012" comment="tog-pegasus-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080003" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0003: e2fsprogs security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0003-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0003.html" />
          <reference source="CVE" ref_id="CVE-2007-5497" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5497.html" />
    
    <description>The e2fsprogs packages contain a number of utilities for creating,
checking, modifying, and correcting any inconsistencies in second and third
extended (ext2/ext3) file systems.

Multiple integer overflow flaws were found in the way e2fsprogs processes
file system content. If a victim opens a carefully crafted file system with
a program using e2fsprogs, it may be possible to execute arbitrary code
with the permissions of the victim. It may be possible to leverage this
flaw in a virtualized environment to gain access to other virtualized
hosts. (CVE-2007-5497)

Red Hat would like to thank Rafal Wojtczuk of McAfee Avert Research for
responsibly disclosing these issues.

Users of e2fsprogs are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-07" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5497.html">CVE-2007-5497</cve>
                <bugzilla href="http://bugzilla.redhat.com/403441" id="403441">CVE-2007-5497 e2fsprogs multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003006" comment="e2fsprogs-devel is earlier than 0:1.39-10.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003007" comment="e2fsprogs-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003002" comment="e2fsprogs is earlier than 0:1.39-10.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003003" comment="e2fsprogs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003004" comment="e2fsprogs-libs is earlier than 0:1.39-10.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003005" comment="e2fsprogs-libs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003011" comment="e2fsprogs-devel is earlier than 0:1.32-15.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003012" comment="e2fsprogs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003009" comment="e2fsprogs is earlier than 0:1.32-15.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003010" comment="e2fsprogs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003015" comment="e2fsprogs-devel is earlier than 0:1.35-12.11.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003012" comment="e2fsprogs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003014" comment="e2fsprogs is earlier than 0:1.35-12.11.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080003010" comment="e2fsprogs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080005" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0005: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0005.html" />
          <reference source="CVE" ref_id="CVE-2007-3847" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3847.html" />
          <reference source="CVE" ref_id="CVE-2007-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4465.html" />
          <reference source="CVE" ref_id="CVE-2007-5000" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5000.html" />
          <reference source="CVE" ref_id="CVE-2007-6388" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6388.html" />
          <reference source="CVE" ref_id="CVE-2008-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0005.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_imap module. On sites where mod_imap was
enabled and an imagemap file was publicly available, a cross-site scripting
attack was possible. (CVE-2007-5000)

A flaw was found in the mod_autoindex module. On sites where directory
listings are used, and the "AddDefaultCharset" directive has been removed
from the configuration, a cross-site scripting attack was possible against
Web browsers which did not correctly derive the response character set
following the rules in RFC 2616. (CVE-2007-4465)

A flaw was found in the mod_proxy module. On sites where a reverse proxy is
configured, a remote attacker could send a carefully crafted request that
would cause the Apache child process handling that request to crash. On
sites where a forward proxy is configured, an attacker could cause a
similar crash if a user could be persuaded to visit a malicious site using
the proxy. This could lead to a denial of service if using a threaded
Multi-Processing Module. (CVE-2007-3847) 

A flaw was found in the mod_status module. On sites where mod_status was
enabled and the status pages were publicly available, a cross-site
scripting attack was possible. (CVE-2007-6388)

A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp
was enabled and a forward proxy was configured, a cross-site scripting
attack was possible against Web browsers which did not correctly derive the
response character set following the rules in RFC 2616. (CVE-2008-0005)

Users of Apache httpd should upgrade to these updated packages, which
contain backported patches to resolve these issues. Users should restart
httpd after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3847.html">CVE-2007-3847</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4465.html">CVE-2007-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5000.html">CVE-2007-5000</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6388.html">CVE-2007-6388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0005.html">CVE-2008-0005</cve>
                <bugzilla href="http://bugzilla.redhat.com/250731" id="250731">CVE-2007-3847 httpd out of bounds read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/289511" id="289511">CVE-2007-4465 mod_autoindex XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/419931" id="419931">CVE-2007-5000 mod_imagemap XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427228" id="427228">CVE-2007-6388 apache mod_status cross-site scripting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427739" id="427739">CVE-2008-0005 mod_proxy_ftp XSS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080005006" comment="httpd-devel is earlier than 0:2.0.46-70.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080005004" comment="mod_ssl is earlier than 0:2.0.46-70.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080005002" comment="httpd is earlier than 0:2.0.46-70.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080006" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0006: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0006-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0006.html" />
          <reference source="CVE" ref_id="CVE-2007-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4465.html" />
          <reference source="CVE" ref_id="CVE-2007-5000" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5000.html" />
          <reference source="CVE" ref_id="CVE-2007-6388" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6388.html" />
          <reference source="CVE" ref_id="CVE-2008-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0005.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_imap module. On sites where mod_imap was
enabled and an imagemap file was publicly available, a cross-site scripting
attack was possible. (CVE-2007-5000)

A flaw was found in the mod_autoindex module. On sites where directory
listings are used, and the "AddDefaultCharset" directive has been removed
from the configuration, a cross-site scripting attack was possible against
Web browsers which do not correctly derive the response character set
following the rules in RFC 2616. (CVE-2007-4465)

A flaw was found in the mod_status module. On sites where mod_status was
enabled and the status pages were publicly available, a cross-site
scripting attack was possible. (CVE-2007-6388)

A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp
was enabled and a forward proxy was configured, a cross-site scripting
attack was possible against Web browsers which do not correctly derive the
response character set following the rules in RFC 2616. (CVE-2008-0005)

Users of Apache httpd should upgrade to these updated packages, which
contain backported patches to resolve these issues. Users should restart
httpd after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4465.html">CVE-2007-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5000.html">CVE-2007-5000</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6388.html">CVE-2007-6388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0005.html">CVE-2008-0005</cve>
                <bugzilla href="http://bugzilla.redhat.com/289511" id="289511">CVE-2007-4465 mod_autoindex XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/419931" id="419931">CVE-2007-5000 mod_imagemap XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427228" id="427228">CVE-2007-6388 apache mod_status cross-site scripting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427739" id="427739">CVE-2008-0005 mod_proxy_ftp XSS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080006010" comment="httpd-manual is earlier than 0:2.0.52-38.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080006011" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080006008" comment="httpd-suexec is earlier than 0:2.0.52-38.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080006009" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080006006" comment="httpd-devel is earlier than 0:2.0.52-38.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080006004" comment="mod_ssl is earlier than 0:2.0.52-38.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080006002" comment="httpd is earlier than 0:2.0.52-38.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080008" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0008: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0008-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0008.html" />
          <reference source="CVE" ref_id="CVE-2007-4465" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4465.html" />
          <reference source="CVE" ref_id="CVE-2007-5000" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5000.html" />
          <reference source="CVE" ref_id="CVE-2007-6388" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6388.html" />
          <reference source="CVE" ref_id="CVE-2007-6421" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6421.html" />
          <reference source="CVE" ref_id="CVE-2007-6422" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6422.html" />
          <reference source="CVE" ref_id="CVE-2008-0005" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0005.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_imagemap module. On sites where mod_imagemap
was enabled and an imagemap file was publicly available, a cross-site
scripting attack was possible. (CVE-2007-5000)

A flaw was found in the mod_autoindex module. On sites where directory
listings are used, and the "AddDefaultCharset" directive has been removed
from the configuration, a cross-site scripting attack might have been
possible against Web browsers which do not correctly derive the response
character set following the rules in RFC 2616. (CVE-2007-4465)

A flaw was found in the mod_status module. On sites where mod_status was
enabled and the status pages were publicly available, a cross-site
scripting attack was possible. (CVE-2007-6388)

A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, a cross-site scripting attack against an
authorized user was possible. (CVE-2007-6421)

A flaw was found in the mod_proxy_balancer module. On sites where
mod_proxy_balancer was enabled, an authorized user could send a carefully
crafted request that would cause the Apache child process handling that
request to crash. This could lead to a denial of service if using a
threaded Multi-Processing Module. (CVE-2007-6422) 

A flaw was found in the mod_proxy_ftp module. On sites where mod_proxy_ftp
was enabled and a forward proxy was configured, a cross-site scripting
attack was possible against Web browsers which do not correctly derive the
response character set following the rules in RFC 2616. (CVE-2008-0005)

Users of Apache httpd should upgrade to these updated packages, which
contain backported patches to resolve these issues. Users should restart
httpd after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-15" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4465.html">CVE-2007-4465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5000.html">CVE-2007-5000</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6388.html">CVE-2007-6388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6421.html">CVE-2007-6421</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6422.html">CVE-2007-6422</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0005.html">CVE-2008-0005</cve>
                <bugzilla href="http://bugzilla.redhat.com/289511" id="289511">CVE-2007-4465 mod_autoindex XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/419931" id="419931">CVE-2007-5000 mod_imagemap XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427228" id="427228">CVE-2007-6388 apache mod_status cross-site scripting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427229" id="427229">CVE-2007-6421 httpd mod_proxy_balancer cross-site scripting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427230" id="427230">CVE-2007-6422 httpd mod_proxy_balancer crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427739" id="427739">CVE-2008-0005 mod_proxy_ftp XSS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080008006" comment="httpd-manual is earlier than 0:2.2.3-11.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008007" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080008004" comment="httpd-devel is earlier than 0:2.2.3-11.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008005" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080008008" comment="mod_ssl is earlier than 0:2.2.3-11.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008009" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080008002" comment="httpd is earlier than 0:2.2.3-11.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080029" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0029: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0029-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0029.html" />
          <reference source="CVE" ref_id="CVE-2007-4568" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4568.html" />
          <reference source="CVE" ref_id="CVE-2007-4990" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4990.html" />
          <reference source="CVE" ref_id="CVE-2007-5958" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5958.html" />
          <reference source="CVE" ref_id="CVE-2007-6427" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6427.html" />
          <reference source="CVE" ref_id="CVE-2007-6428" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6428.html" />
          <reference source="CVE" ref_id="CVE-2007-6429" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6429.html" />
          <reference source="CVE" ref_id="CVE-2008-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0006.html" />
    
    <description>XFree86 is an implementation of the X Window System, which provides the
core functionality for the Linux graphical desktop.

Two integer overflow flaws were found in the XFree86 server's EVI and
MIT-SHM modules. A malicious authorized client could exploit these issues
to cause a denial of service (crash), or potentially execute arbitrary code
with root privileges on the XFree86 server. (CVE-2007-6429)

A heap based buffer overflow flaw was found in the way the XFree86 server
handled malformed font files. A malicious local user could exploit this
issue to potentially execute arbitrary code with the privileges of the
XFree86 server. (CVE-2008-0006)

A memory corruption flaw was found in the XFree86 server's XInput
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the XFree86 server. (CVE-2007-6427)

An information disclosure flaw was found in the XFree86 server's TOG-CUP
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially view arbitrary memory content
within the XFree86 server's address space. (CVE-2007-6428)

An integer and heap overflow flaw were found in the X.org font server, xfs.
A user with the ability to connect to the font server could have been able
to cause a denial of service (crash), or potentially execute arbitrary code
with the permissions of the font server. (CVE-2007-4568, CVE-2007-4990)

A flaw was found in the XFree86 server's XC-SECURITY extension, that could
have allowed a local user to verify the existence of an arbitrary file,
even in directories that are not normally accessible to that user.
(CVE-2007-5958)

Users of XFree86 are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-18" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4568.html">CVE-2007-4568</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4990.html">CVE-2007-4990</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5958.html">CVE-2007-5958</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6427.html">CVE-2007-6427</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6428.html">CVE-2007-6428</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6429.html">CVE-2007-6429</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0006.html">CVE-2008-0006</cve>
                <bugzilla href="http://bugzilla.redhat.com/281921" id="281921">CVE-2007-4568 xfs integer overflow in the build_range function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/322961" id="322961">CVE-2007-4990 xfs heap overflow in the swap_char2b function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/391841" id="391841">CVE-2007-5958 Xorg / XFree86 file existence disclosure vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413721" id="413721">CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413741" id="413741">CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413791" id="413791">CVE-2007-6428 xorg / xfree86: information disclosure via TOG-CUP extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413811" id="413811">CVE-2007-6427 xorg / xfree86: memory corruption via XInput extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428044" id="428044">CVE-2008-0006 Xorg / XFree86 PCF font parser buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029052" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029053" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029022" comment="XFree86-xdm is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029023" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029024" comment="XFree86-libs-data is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029025" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029008" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029009" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029006" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029007" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029042" comment="XFree86-doc is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029043" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029038" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029039" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029034" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029035" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029002" comment="XFree86 is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029060" comment="XFree86-libs is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029061" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029056" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029057" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029046" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029032" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029033" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029018" comment="XFree86-sdk is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029019" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029010" comment="XFree86-xfs is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029011" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029036" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029037" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029028" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029029" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029014" comment="XFree86-Xnest is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029015" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029050" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029051" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029004" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029005" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029054" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029055" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029044" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029045" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029058" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029059" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029048" comment="XFree86-font-utils is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029049" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029030" comment="XFree86-base-fonts is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029031" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029040" comment="XFree86-Xvfb is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029041" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029026" comment="XFree86-twm is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029027" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029016" comment="XFree86-tools is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029017" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029020" comment="XFree86-xauth is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029021" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080029012" comment="XFree86-devel is earlier than 0:4.3.0-126.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080030" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0030: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0030-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0030.html" />
          <reference source="CVE" ref_id="CVE-2007-4568" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4568.html" />
          <reference source="CVE" ref_id="CVE-2007-4990" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4990.html" />
          <reference source="CVE" ref_id="CVE-2007-5760" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5760.html" />
          <reference source="CVE" ref_id="CVE-2007-5958" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5958.html" />
          <reference source="CVE" ref_id="CVE-2007-6427" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6427.html" />
          <reference source="CVE" ref_id="CVE-2007-6428" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6428.html" />
          <reference source="CVE" ref_id="CVE-2007-6429" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6429.html" />
          <reference source="CVE" ref_id="CVE-2008-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0006.html" />
    
    <description>The xorg-x11 packages contain X.Org, an open source implementation of the X
Window System. It provides the basic low-level functionality that
full-fledged graphical user interfaces are designed upon.

Two integer overflow flaws were found in the X.Org server's EVI and MIT-SHM
modules. A malicious authorized client could exploit these issues to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-6429)

A heap based buffer overflow flaw was found in the way the X.Org server
handled malformed font files. A malicious local user could exploit these
issues to potentially execute arbitrary code with the privileges of the
X.Org server. (CVE-2008-0006)

A memory corruption flaw was found in the X.Org server's XInput extension.
A malicious authorized client could exploit this issue to cause a denial of
service (crash), or potentially execute arbitrary code with root privileges
on the X.Org server. (CVE-2007-6427)

An input validation flaw was found in the X.Org server's XFree86-Misc
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-5760)

An information disclosure flaw was found in the X.Org server's TOG-CUP
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially view arbitrary memory content
within the X server's address space. (CVE-2007-6428)

An integer and heap overflow flaw were found in the X.Org font server, xfs.
A user with the ability to connect to the font server could have been able
to cause a denial of service (crash), or potentially execute arbitrary code
with the permissions of the font server. (CVE-2007-4568, CVE-2007-4990)

A flaw was found in the X.Org server's XC-SECURITY extension, that could
have allowed a local user to verify the existence of an arbitrary file,
even in directories that are not normally accessible to that user.
(CVE-2007-5958)

Users of xorg-x11 should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-17" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4568.html">CVE-2007-4568</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4990.html">CVE-2007-4990</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5760.html">CVE-2007-5760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5958.html">CVE-2007-5958</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6427.html">CVE-2007-6427</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6428.html">CVE-2007-6428</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6429.html">CVE-2007-6429</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0006.html">CVE-2008-0006</cve>
                <bugzilla href="http://bugzilla.redhat.com/281921" id="281921">CVE-2007-4568 xfs integer overflow in the build_range function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/322961" id="322961">CVE-2007-4990 xfs heap overflow in the swap_char2b function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/391841" id="391841">CVE-2007-5958 Xorg / XFree86 file existence disclosure vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413721" id="413721">CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413741" id="413741">CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413791" id="413791">CVE-2007-6428 xorg / xfree86: information disclosure via TOG-CUP extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413811" id="413811">CVE-2007-6427 xorg / xfree86: memory corruption via XInput extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414031" id="414031">CVE-2007-5760 xorg: invalid array indexing in XFree86-Misc extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428044" id="428044">CVE-2008-0006 Xorg / XFree86 PCF font parser buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030036" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030037" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030010" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030011" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030004" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030005" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030028" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030029" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030020" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030021" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030016" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030017" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030014" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030015" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030026" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030027" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030034" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030035" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030008" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030009" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030032" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030033" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030024" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030025" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030018" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030019" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030006" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030007" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030030" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030031" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030022" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030023" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080030012" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030013" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080031" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0031: xorg-x11-server security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0031-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0031.html" />
          <reference source="CVE" ref_id="CVE-2007-5760" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5760.html" />
          <reference source="CVE" ref_id="CVE-2007-5958" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5958.html" />
          <reference source="CVE" ref_id="CVE-2007-6427" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6427.html" />
          <reference source="CVE" ref_id="CVE-2007-6428" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6428.html" />
          <reference source="CVE" ref_id="CVE-2007-6429" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6429.html" />
    
    <description>X.Org is an open source implementation of the X Window System. It provides
basic low-level functionality that full-fledged graphical user interfaces
are designed upon.

Two integer overflow flaws were found in the X.Org server's EVI and MIT-SHM
modules. A malicious authorized client could exploit these issues to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-6429)

A memory corruption flaw was found in the X.Org server's XInput extension.
A malicious authorized client could exploit this issue to cause a denial of
service (crash), or potentially execute arbitrary code with root privileges
on the X.Org server. (CVE-2007-6427)

An input validation flaw was found in the X.Org server's XFree86-Misc
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially execute arbitrary code with
root privileges on the X.Org server. (CVE-2007-5760)

An information disclosure flaw was found in the X.Org server's TOG-CUP
extension. A malicious authorized client could exploit this issue to cause
a denial of service (crash), or potentially view arbitrary memory content
within the X server's address space. (CVE-2007-6428)

A flaw was found in the X.Org server's XC-SECURITY extension, that could
have allowed a local user to verify the existence of an arbitrary file,
even in directories that are not normally accessible to that user.
(CVE-2007-5958)

Users of xorg-x11-server should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-17" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5760.html">CVE-2007-5760</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5958.html">CVE-2007-5958</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6427.html">CVE-2007-6427</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6428.html">CVE-2007-6428</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6429.html">CVE-2007-6429</cve>
                <bugzilla href="http://bugzilla.redhat.com/391841" id="391841">CVE-2007-5958 Xorg / XFree86 file existence disclosure vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413721" id="413721">CVE-2007-6429 xorg / xfree86: integer overflow in EVI extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413741" id="413741">CVE-2007-6429 xorg / xfree86: integer overflow in MIT-SHM extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413791" id="413791">CVE-2007-6428 xorg / xfree86: information disclosure via TOG-CUP extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413811" id="413811">CVE-2007-6427 xorg / xfree86: memory corruption via XInput extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414031" id="414031">CVE-2007-5760 xorg: invalid array indexing in XFree86-Misc extension</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031014" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031015" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031010" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031011" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031004" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031005" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031008" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031009" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031012" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031013" comment="xorg-x11-server-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031002" comment="xorg-x11-server is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031003" comment="xorg-x11-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080031006" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.26.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031007" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080032" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0032: libxml2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0032-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0032.html" />
          <reference source="CVE" ref_id="CVE-2007-6284" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6284.html" />
    
    <description>The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.

A denial of service flaw was found in the way libxml2 processes certain
content. If an application linked against libxml2 processes malformed XML
content, it could cause the application to stop responding. (CVE-2007-6284)

Red Hat would like to thank the Google Security Team for responsibly
disclosing this issue.

All users are advised to upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-11" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6284.html">CVE-2007-6284</cve>
                <bugzilla href="http://bugzilla.redhat.com/425927" id="425927">CVE-2007-6284 libxml2: infinite loop in UTF-8 decoding</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032002" comment="libxml2 is earlier than 0:2.6.26-2.1.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032003" comment="libxml2 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032004" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032005" comment="libxml2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032006" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032007" comment="libxml2-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032009" comment="libxml2 is earlier than 0:2.5.10-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032011" comment="libxml2-devel is earlier than 0:2.5.10-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032013" comment="libxml2-python is earlier than 0:2.5.10-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032016" comment="libxml2 is earlier than 0:2.6.16-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032017" comment="libxml2-devel is earlier than 0:2.6.16-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080032018" comment="libxml2-python is earlier than 0:2.6.16-10.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080038" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0038: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0038-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0038.html" />
          <reference source="CVE" ref_id="CVE-2007-3278" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3278.html" />
          <reference source="CVE" ref_id="CVE-2007-4769" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4769.html" />
          <reference source="CVE" ref_id="CVE-2007-4772" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4772.html" />
          <reference source="CVE" ref_id="CVE-2007-6067" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6067.html" />
          <reference source="CVE" ref_id="CVE-2007-6600" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6600.html" />
          <reference source="CVE" ref_id="CVE-2007-6601" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6601.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS). The postgresql packages include the client programs and libraries
needed to access a PostgreSQL DBMS server.

Will Drewry discovered multiple flaws in PostgreSQL's regular expression
engine. An authenticated attacker could use these flaws to cause a denial
of service by causing the PostgreSQL server to crash, enter an infinite
loop, or use extensive CPU and memory resources while processing queries
containing specially crafted regular expressions. Applications that accept
regular expressions from untrusted sources may expose this problem to
unauthorized attackers. (CVE-2007-4769, CVE-2007-4772, CVE-2007-6067)

A privilege escalation flaw was discovered in PostgreSQL. An authenticated
attacker could create an index function that would be executed with
administrator privileges during database maintenance tasks, such as
database vacuuming. (CVE-2007-6600)

A privilege escalation flaw was discovered in PostgreSQL's Database Link
library (dblink). An authenticated attacker could use dblink to possibly
escalate privileges on systems with "trust" or "ident" authentication
configured. Please note that dblink functionality is not enabled by
default, and can only by enabled by a database administrator on systems
with the postgresql-contrib package installed. (CVE-2007-3278,
CVE-2007-6601)

All postgresql users should upgrade to these updated packages, which
include PostgreSQL 7.4.19 and 8.1.11, and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-11" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3278.html">CVE-2007-3278</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4769.html">CVE-2007-4769</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4772.html">CVE-2007-4772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6067.html">CVE-2007-6067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6600.html">CVE-2007-6600</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6601.html">CVE-2007-6601</cve>
                <bugzilla href="http://bugzilla.redhat.com/309141" id="309141">CVE-2007-3278 dblink allows proxying of database connections via 127.0.0.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/315231" id="315231">CVE-2007-4769 postgresql integer overflow in regex code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/316511" id="316511">CVE-2007-4772 postgresql DoS via infinite loop in regex NFA optimization code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/400931" id="400931">CVE-2007-6067 postgresql: tempory DoS caused by slow regex NFA cleanup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427127" id="427127">CVE-2007-6600 PostgreSQL privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427128" id="427128">CVE-2007-6601 PostgreSQL privilege escalation via dblink</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038018" comment="postgresql-docs is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038019" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038004" comment="postgresql-devel is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038005" comment="postgresql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038020" comment="postgresql-contrib is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038021" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038016" comment="postgresql-test is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038017" comment="postgresql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038008" comment="postgresql-libs is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038009" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038012" comment="postgresql-tcl is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038013" comment="postgresql-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038002" comment="postgresql is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038003" comment="postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038014" comment="postgresql-pl is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038015" comment="postgresql-pl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038010" comment="postgresql-python is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038011" comment="postgresql-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038006" comment="postgresql-server is earlier than 0:8.1.11-1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038007" comment="postgresql-server is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038035" comment="postgresql-jdbc is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038036" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038029" comment="postgresql-docs is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038030" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038025" comment="postgresql-devel is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038026" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038039" comment="postgresql-test is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038040" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038031" comment="postgresql-contrib is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038032" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038041" comment="postgresql-libs is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038042" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038043" comment="postgresql-tcl is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038044" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038023" comment="postgresql is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038024" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038037" comment="postgresql-python is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038038" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038033" comment="postgresql-server is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038034" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080038027" comment="postgresql-pl is earlier than 0:7.4.19-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080038028" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080039" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0039: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0039.html" />
          <reference source="CVE" ref_id="CVE-2007-3278" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3278.html" />
          <reference source="CVE" ref_id="CVE-2007-6600" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6600.html" />
          <reference source="CVE" ref_id="CVE-2007-6601" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6601.html" />
    
    <description>PostgreSQL is an advanced Object-Relational database management system
(DBMS). The postgresql packages include the client programs and libraries
needed to access a PostgreSQL DBMS server.

A privilege escalation flaw was discovered in PostgreSQL. An authenticated
attacker could create an index function that would be executed with
administrator privileges during database maintenance tasks, such as
database vacuuming. (CVE-2007-6600)

A privilege escalation flaw was discovered in PostgreSQL's Database Link
library (dblink). An authenticated attacker could use dblink to possibly
escalate privileges on systems with "trust" or "ident" authentication
configured. Please note that dblink functionality is not enabled by
default, and can only by enabled by a database administrator on systems
with the postgresql-contrib package installed.
(CVE-2007-3278, CVE-2007-6601)

All postgresql users should upgrade to these updated packages, which
include PostgreSQL 7.3.21 and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-11" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3278.html">CVE-2007-3278</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6600.html">CVE-2007-6600</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6601.html">CVE-2007-6601</cve>
                <bugzilla href="http://bugzilla.redhat.com/309141" id="309141">CVE-2007-3278 dblink allows proxying of database connections via 127.0.0.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427127" id="427127">CVE-2007-6600 PostgreSQL privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427128" id="427128">CVE-2007-6601 PostgreSQL privilege escalation via dblink</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039018" comment="rh-postgresql-docs is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039019" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039004" comment="rh-postgresql-jdbc is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039005" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039010" comment="rh-postgresql-contrib is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039011" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039002" comment="rh-postgresql is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039016" comment="rh-postgresql-devel is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039017" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039014" comment="rh-postgresql-pl is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039015" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039006" comment="rh-postgresql-python is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039007" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039022" comment="rh-postgresql-libs is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039023" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039020" comment="rh-postgresql-tcl is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039021" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039012" comment="rh-postgresql-test is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039013" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080039008" comment="rh-postgresql-server is earlier than 0:7.3.21-1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080039009" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080042" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0042: tomcat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0042-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0042.html" />
          <reference source="CVE" ref_id="CVE-2007-5461" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5461.html" />
          <reference source="CVE" ref_id="CVE-2007-5342" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5342.html" />
    
    <description>Tomcat is a servlet container for Java Servlet and JavaServer Pages
technologies.

A directory traversal vulnerability existed in the Apache Tomcat webdav
servlet. In some configurations it allowed remote authenticated users to
read files accessible to the local tomcat process. (CVE-2007-5461)

The default security policy in the JULI logging component did not restrict
access permissions to files. This could be misused by untrusted web
applications to access and write arbitrary files in the context of the
tomcat process. (CVE-2007-5342)

Users of Tomcat should update to these errata packages, which contain
backported patches and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-11" />
        <updated date="2008-03-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5461.html">CVE-2007-5461</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5342.html">CVE-2007-5342</cve>
                <bugzilla href="http://bugzilla.redhat.com/333791" id="333791">CVE-2007-5461 Absolute path traversal Apache Tomcat WEBDAV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427216" id="427216">CVE-2007-5342 Apache Tomcat's default security policy is too open</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042012" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042013" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042004" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042005" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042022" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042023" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042016" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042017" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042006" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042007" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042020" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042021" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042008" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042009" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042014" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042015" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042018" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042019" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042010" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042011" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080042002" comment="tomcat5 is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042003" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080055" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0055: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0055-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0055.html" />
          <reference source="CVE" ref_id="CVE-2007-4130" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4130.html" />
          <reference source="CVE" ref_id="CVE-2007-5500" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5500.html" />
          <reference source="CVE" ref_id="CVE-2007-6063" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6063.html" />
          <reference source="CVE" ref_id="CVE-2007-6151" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6151.html" />
          <reference source="CVE" ref_id="CVE-2007-6206" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6206.html" />
          <reference source="CVE" ref_id="CVE-2007-6694" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6694.html" />
          <reference source="CVE" ref_id="CVE-2008-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0001.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated kernel packages fix the following security issues:

A flaw was found in the virtual filesystem (VFS). A local unprivileged
user could truncate directories to which they had write permission; this
could render the contents of the directory inaccessible. (CVE-2008-0001,
Important)

A flaw was found in the implementation of ptrace. A local unprivileged user
could trigger this flaw and possibly cause a denial of service (system
hang). (CVE-2007-5500, Important)

A flaw was found in the way the Red Hat Enterprise Linux 4 kernel handled
page faults when a CPU used the NUMA method for accessing memory on Itanium
architectures. A local unprivileged user could trigger this flaw and cause
a denial of service (system panic). (CVE-2007-4130, Important)

A possible NULL pointer dereference was found in the chrp_show_cpuinfo
function when using the PowerPC architecture. This may have allowed a local
unprivileged user to cause a denial of service (crash).
(CVE-2007-6694, Moderate)

A flaw was found in the way core dump files were created. If a local user
can get a root-owned process to dump a core file into a directory, which
the user has write access to, they could gain read access to that core
file. This could potentially grant unauthorized access to sensitive
information. (CVE-2007-6206, Moderate)

Two buffer overflow flaws were found in the Linux kernel ISDN subsystem. A
local unprivileged  user could use these flaws to cause a denial of
service. (CVE-2007-6063, CVE-2007-6151, Moderate)

As well, these updated packages fix the following bug:

* when moving volumes that contain multiple segments, and a mirror segment
is not the first in the mapping table, running the "pvmove /dev/[device]
/dev/[device]" command caused a kernel panic. A "kernel: Unable to handle
kernel paging request at virtual address [address]" error was logged by
syslog.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-31" />
        <updated date="2008-01-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4130.html">CVE-2007-4130</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5500.html">CVE-2007-5500</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6063.html">CVE-2007-6063</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6151.html">CVE-2007-6151</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6206.html">CVE-2007-6206</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6694.html">CVE-2007-6694</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0001.html">CVE-2008-0001</cve>
                <bugzilla href="http://bugzilla.redhat.com/179665" id="179665">CVE-2007-4130 panic caused by set_mempolicy with MPOL_BIND</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382161" id="382161">CVE-2007-5500 kernel hang via userspace PTRACE+waitid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/392101" id="392101">CVE-2007-6063 Linux Kernel isdn_net_setcfg buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396751" id="396751">CVE-2007-6694 /proc/cpuinfo DoS on some ppc machines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396861" id="396861">CVE-2007-6206 Issue with core dump owner</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425111" id="425111">CVE-2007-6151 I4L: fix isdn_ioctl memory issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428637" id="428637">pvmove causes kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428791" id="428791">CVE-2008-0001 kernel: filesystem corruption by unprivileged user via directory truncation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055002" comment="kernel is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055022" comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055004" comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055006" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055020" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055014" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055008" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055016" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055010" comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080055012" comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080058" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0058: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0058-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0058.html" />
          <reference source="CVE" ref_id="CVE-2007-6111" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6111.html" />
          <reference source="CVE" ref_id="CVE-2007-6112" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6112.html" />
          <reference source="CVE" ref_id="CVE-2007-6113" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6113.html" />
          <reference source="CVE" ref_id="CVE-2007-6114" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6114.html" />
          <reference source="CVE" ref_id="CVE-2007-6115" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6115.html" />
          <reference source="CVE" ref_id="CVE-2007-6116" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6116.html" />
          <reference source="CVE" ref_id="CVE-2007-6117" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6117.html" />
          <reference source="CVE" ref_id="CVE-2007-6118" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6118.html" />
          <reference source="CVE" ref_id="CVE-2007-6119" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6119.html" />
          <reference source="CVE" ref_id="CVE-2007-6120" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6120.html" />
          <reference source="CVE" ref_id="CVE-2007-6121" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6121.html" />
          <reference source="CVE" ref_id="CVE-2007-6438" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6438.html" />
          <reference source="CVE" ref_id="CVE-2007-6439" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6439.html" />
          <reference source="CVE" ref_id="CVE-2007-6441" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6441.html" />
          <reference source="CVE" ref_id="CVE-2007-6450" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6450.html" />
          <reference source="CVE" ref_id="CVE-2007-6451" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6451.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Several flaws were found in Wireshark. Wireshark could crash or possibly
execute arbitrary code as the user running Wireshark if it read a malformed
packet off the network. (CVE-2007-6112, CVE-2007-6114, CVE-2007-6115,
CVE-2007-6117)

Several denial of service bugs were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off the network.
(CVE-2007-6111, CVE-2007-6113, CVE-2007-6116, CVE-2007-6118, CVE-2007-6119,
CVE-2007-6120, CVE-2007-6121, CVE-2007-6438, CVE-2007-6439, CVE-2007-6441,
CVE-2007-6450, CVE-2007-6451)

As well, Wireshark switched from using net-snmp to libsmi, which is
included in this errata.

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 0.99.7, and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-21" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6111.html">CVE-2007-6111</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6112.html">CVE-2007-6112</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6113.html">CVE-2007-6113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6114.html">CVE-2007-6114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6115.html">CVE-2007-6115</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6116.html">CVE-2007-6116</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6117.html">CVE-2007-6117</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6118.html">CVE-2007-6118</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6119.html">CVE-2007-6119</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6120.html">CVE-2007-6120</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6121.html">CVE-2007-6121</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6438.html">CVE-2007-6438</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6439.html">CVE-2007-6439</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6441.html">CVE-2007-6441</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6450.html">CVE-2007-6450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6451.html">CVE-2007-6451</cve>
                <bugzilla href="http://bugzilla.redhat.com/397251" id="397251">CVE-2007-6111 wireshark mp3 and ncp flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397271" id="397271">CVE-2007-6112 wireshark ppp flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397281" id="397281">CVE-2007-6113 wireshark DNP3 flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397291" id="397291">CVE-2007-6114 wireshark SSL and OS/400 trace flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397311" id="397311">CVE-2007-6115 wireshark ANSI MAP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397321" id="397321">CVE-2007-6116 wireshark firebird/interbase flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397331" id="397331">CVE-2007-6117 wireshark HTTP dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397341" id="397341">CVE-2007-6118 wireshark MEGACO dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397351" id="397351">CVE-2007-6119 wireshark DCP ETSI dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397361" id="397361">CVE-2007-6120 wireshark Bluetooth SDP dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397371" id="397371">CVE-2007-6121 wireshark RPC Portmap flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426335" id="426335">Please consider adding libsmi to distro</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426336" id="426336">Please consider adding libsmi to distro</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427249" id="427249">CVE-2007-6438 wireshark SMB dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427251" id="427251">CVE-2007-6439 wireshark IPv6 and USB dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427252" id="427252">CVE-2007-6441 wireshark WiMAX dissector possible crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427253" id="427253">CVE-2007-6450 wireshark RPL dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427254" id="427254">CVE-2007-6451 wireshark CIP dissector crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058002" comment="wireshark is earlier than 0:0.99.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058004" comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058008" comment="libsmi-devel is earlier than 0:0.4.5-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058009" comment="libsmi-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058006" comment="libsmi is earlier than 0:0.4.5-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058007" comment="libsmi is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058011" comment="wireshark is earlier than 0:0.99.7-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058012" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058013" comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058014" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058017" comment="libsmi-devel is earlier than 0:0.4.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058018" comment="libsmi-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080058015" comment="libsmi is earlier than 0:0.4.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058016" comment="libsmi is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080059" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0059: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0059-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0059.html" />
          <reference source="CVE" ref_id="CVE-2007-3389" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3389.html" />
          <reference source="CVE" ref_id="CVE-2007-3390" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3390.html" />
          <reference source="CVE" ref_id="CVE-2007-3391" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3391.html" />
          <reference source="CVE" ref_id="CVE-2007-3392" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3392.html" />
          <reference source="CVE" ref_id="CVE-2007-3393" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3393.html" />
          <reference source="CVE" ref_id="CVE-2007-6113" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6113.html" />
          <reference source="CVE" ref_id="CVE-2007-6114" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6114.html" />
          <reference source="CVE" ref_id="CVE-2007-6115" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6115.html" />
          <reference source="CVE" ref_id="CVE-2007-6117" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6117.html" />
          <reference source="CVE" ref_id="CVE-2007-6118" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6118.html" />
          <reference source="CVE" ref_id="CVE-2007-6120" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6120.html" />
          <reference source="CVE" ref_id="CVE-2007-6121" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6121.html" />
          <reference source="CVE" ref_id="CVE-2007-6450" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6450.html" />
          <reference source="CVE" ref_id="CVE-2007-6451" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6451.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Several flaws were found in Wireshark. Wireshark could crash or possibly
execute arbitrary code as the user running Wireshark if it read a malformed
packet off the network. (CVE-2007-6114, CVE-2007-6115, CVE-2007-6117)

Several denial of service bugs were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off the network.
(CVE-2007-3389, CVE-2007-3390, CVE-2007-3391, CVE-2007-3392, CVE-2007-3392,
CVE-2007-3393, CVE-2007-6113, CVE-2007-6118, CVE-2007-6120, CVE-2007-6121,
CVE-2007-6450, CVE-2007-6451)

As well, Wireshark switched from using net-snmp to libsmi, which is
included in this errata.

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 0.99.7, and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-21" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3389.html">CVE-2007-3389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3390.html">CVE-2007-3390</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3391.html">CVE-2007-3391</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3392.html">CVE-2007-3392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3393.html">CVE-2007-3393</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6113.html">CVE-2007-6113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6114.html">CVE-2007-6114</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6115.html">CVE-2007-6115</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6117.html">CVE-2007-6117</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6118.html">CVE-2007-6118</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6120.html">CVE-2007-6120</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6121.html">CVE-2007-6121</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6450.html">CVE-2007-6450</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6451.html">CVE-2007-6451</cve>
                <bugzilla href="http://bugzilla.redhat.com/245796" id="245796">CVE-2007-3389 Wireshark crashes when inspecting HTTP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245797" id="245797">CVE-2007-3391 Wireshark loops infinitely when inspecting DCP ETSI traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245798" id="245798">CVE-2007-3392 Wireshark loops infinitely when inspecting SSL traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246221" id="246221">CVE-2007-3393 Wireshark corrupts the stack when inspecting BOOTP traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246225" id="246225">CVE-2007-3390 Wireshark crashes when inspecting iSeries traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/246229" id="246229">CVE-2007-3392 Wireshark crashes when inspecting MMS traffic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397281" id="397281">CVE-2007-6113 wireshark DNP3 flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397291" id="397291">CVE-2007-6114 wireshark SSL and OS/400 trace flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397311" id="397311">CVE-2007-6115 wireshark ANSI MAP flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397331" id="397331">CVE-2007-6117 wireshark HTTP dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397341" id="397341">CVE-2007-6118 wireshark MEGACO dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397361" id="397361">CVE-2007-6120 wireshark Bluetooth SDP dissector flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397371" id="397371">CVE-2007-6121 wireshark RPC Portmap flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426337" id="426337">Wireshare rebase requires new libsmi package adding to rhel3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427253" id="427253">CVE-2007-6450 wireshark RPL dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427254" id="427254">CVE-2007-6451 wireshark CIP dissector crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080059004" comment="libsmi-devel is earlier than 0:0.4.5-3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058018" comment="libsmi-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080059002" comment="libsmi is earlier than 0:0.4.5-3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058016" comment="libsmi is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080059006" comment="wireshark is earlier than 0:0.99.7-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058012" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080059008" comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058014" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080061" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0061: setroubleshoot security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0061.html" />
          <reference source="CVE" ref_id="CVE-2007-5495" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5495.html" />
          <reference source="CVE" ref_id="CVE-2007-5496" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5496.html" />
    
    <description>The setroubleshoot packages provide tools to help diagnose SELinux
problems. When AVC messages occur, an alert is generated that gives
information about the problem, and how to create a resolution.

A flaw was found in the way sealert wrote diagnostic messages to a
temporary file. A local unprivileged user could perform a symbolic link
attack, and cause arbitrary files, writable by other users, to be
overwritten when a victim runs sealert. (CVE-2007-5495)

A flaw was found in the way sealert displayed records from the
setroubleshoot database as unescaped HTML. An local unprivileged attacker
could cause AVC denial events with carefully crafted process or file names,
injecting arbitrary HTML tags into the logs, which could be used as a
scripting attack, or to confuse the user running sealert. (CVE-2007-5496)

Additionally, the following bugs have been fixed in these update packages:

* in certain situations, the sealert process used excessive CPU. These
alerts are now capped at a maximum of 30, D-Bus is used instead of polling,
threads causing excessive wake-up have been removed, and more robust
exception-handling has been added.

* different combinations of the sealert '-a', '-l', '-H', and '-v' options
did not work as documented.

* the SETroubleShoot browser did not allow multiple entries to be deleted. 

* the SETroubleShoot browser did not display statements that displayed
whether SELinux was using Enforcing or Permissive mode, particularly when
warning about SELinux preventions.

* in certain cases, the SETroubleShoot browser gave incorrect instructions
regarding paths, and would not display the full paths to files.

* adding an email recipient to the recipients option from the
/etc/setroubleshoot/setroubleshoot.cfg file and then generating an SELinux
denial caused a traceback error. The recipients option has been removed;
email addresses are now managed through the SETroubleShoot browser by
navigating to File -> Edit Email Alert List, or by editing the
/var/lib/setroubleshoot/email_alert_recipients file.

* the setroubleshoot browser incorrectly displayed a period between the
httpd_sys_content_t context and the directory path.

* on the PowerPC architecture, The get_credentials() function in
access_control.py would generate an exception when it called the
socket.getsockopt() function.

* The code which handles path information has been completely rewritten so
that assumptions on path information which were misleading are no longer
made. If the path information is not present, it will be presented as
"&lt;Unknown>".

* setroubleshoot had problems with non-English locales under certain
circumstances, possibly causing a python traceback, an sealert window
pop-up containing an error, a "RuntimeError: maximum recursion depth
exceeded" error after a traceback, or a "UnicodeEncodeError" after a traceback.

* sealert ran even when SELinux was disabled, causing "attempt to open
server connection failed" errors. Sealert now checks whether SELinux is
enabled or disabled.

* the database setroubleshoot maintains was world-readable. The
setroubleshoot database is now mode 600, and is owned by the root user and
group.

* setroubleshoot did not validate requests to set AVC filtering options for
users. In these updated packages, checks ensure that requests originate
from the filter owner.

* the previous setroubleshoot packages required a number of GNOME packages
and libraries. setroubleshoot has therefore been split into 2 packages:
setroubleshoot and setroubleshoot-server.

* a bug in decoding the audit field caused an "Input is not proper UTF-8,
indicate encoding!" error message. The decoding code has been rewritten.

* a file name mismatch in the setroubleshoot init script would cause a
failure to shut down.

Users of setroubleshoot are advised to upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5495.html">CVE-2007-5495</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5496.html">CVE-2007-5496</cve>
                <bugzilla href="http://bugzilla.redhat.com/227806" id="227806">setroubleshoot browser doesn't allow multiple entry deletion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240355" id="240355">setroubleshoot gives bad suggestions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241543" id="241543">Adding recipents entry to config file crashes setroubleshoot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243800" id="243800">typo in sealert / setroubleshoot suggestion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244345" id="244345">missing filename in setroubleshoot (AVC.get_path() returns incomplete path)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250239" id="250239">Runtime Error: maximum recursion depth exceeded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/288221" id="288221">CVE-2007-5495 setroubleshoot insecure logging</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/288271" id="288271">CVE-2007-5496 setroubleshoot log injection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/288881" id="288881">setroubleshoot failure when httpd is trying to access rpm_log_t</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/312281" id="312281">setroubleshoot requires gnome to run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431768" id="431768">setroubleshoot - audit_listener_database.xml:3029: parser error in xmlParseDoc()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436564" id="436564">socket.getsockopt() on ppc generates exception</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080061002" comment="setroubleshoot-plugins is earlier than 0:2.0.4-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080061003" comment="setroubleshoot-plugins is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080061006" comment="setroubleshoot-server is earlier than 0:2.0.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080061007" comment="setroubleshoot-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080061004" comment="setroubleshoot is earlier than 0:2.0.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080061005" comment="setroubleshoot is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080064" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0064: libXfont security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0064-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0064.html" />
          <reference source="CVE" ref_id="CVE-2008-0006" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0006.html" />
    
    <description>The libXfont package contains the X.Org X11 libXfont runtime library.

A heap based buffer overflow flaw was found in the way the X.Org server
handled malformed font files. A malicious local user could exploit this
issue to potentially execute arbitrary code with the privileges of the
X.Org server. (CVE-2008-0006)

Users of X.Org libXfont should upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-17" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0006.html">CVE-2008-0006</cve>
                <bugzilla href="http://bugzilla.redhat.com/428044" id="428044">CVE-2008-0006 Xorg / XFree86 PCF font parser buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080064002" comment="libXfont is earlier than 0:1.2.2-1.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080064003" comment="libXfont is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080064004" comment="libXfont-devel is earlier than 0:1.2.2-1.0.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080064005" comment="libXfont-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080089" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0089: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0089-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0089.html" />
          <reference source="CVE" ref_id="CVE-2007-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3104.html" />
          <reference source="CVE" ref_id="CVE-2007-5904" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5904.html" />
          <reference source="CVE" ref_id="CVE-2007-6206" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6206.html" />
          <reference source="CVE" ref_id="CVE-2007-6416" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6416.html" />
          <reference source="CVE" ref_id="CVE-2008-0001" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0001.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These new kernel packages fix the following security issues:

A flaw was found in the virtual filesystem (VFS). An unprivileged local
user could truncate directories to which they had write permission; this
could render the contents of the directory inaccessible. (CVE-2008-0001,
Important)

A flaw was found in the Xen PAL emulation on Intel 64 platforms. A guest
Hardware-assisted virtual machine (HVM) could read the arbitrary physical
memory of the host system, which could make information available to
unauthorized users. (CVE-2007-6416, Important)

A flaw was found in the way core dump files were created. If a local user
can get a root-owned process to dump a core file into a directory, which
the user has write access to, they could gain read access to that core
file, potentially containing sensitive information. (CVE-2007-6206, Moderate)

A buffer overflow flaw was found in the CIFS virtual file system. A
remote,authenticated user could issue a request that could lead to a denial
of service. (CVE-2007-5904, Moderate)

A flaw was found in the "sysfs_readdir" function. A local user could create
a race condition which would cause a denial of service (kernel oops).
(CVE-2007-3104, Moderate)

As well, these updated packages fix the following bugs:

* running the "strace -f" command caused strace to hang, without displaying
information about child processes.

* unmounting an unresponsive, interruptable NFS mount, for example, one
mounted with the "intr" option, may have caused a system crash.

* a bug in the s2io.ko driver prevented VLAN devices from being added.
Attempting to add a device to a VLAN, for example, running the "vconfig
add [device-name] [vlan-id]" command caused vconfig to fail.

* tux used an incorrect open flag bit. This caused problems when building
packages in a chroot environment, such as mock, which is used by the koji
build system.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-23" />
        <updated date="2008-03-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3104.html">CVE-2007-3104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5904.html">CVE-2007-5904</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6206.html">CVE-2007-6206</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6416.html">CVE-2007-6416</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0001.html">CVE-2008-0001</cve>
                <bugzilla href="http://bugzilla.redhat.com/245777" id="245777">CVE-2007-3104 Null pointer to an inode in a dentry can cause an oops in sysfs_readdir [rhel-5.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/372701" id="372701">CVE-2007-5904 Buffer overflow in CIFS VFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396861" id="396861">CVE-2007-6206 Issue with core dump owner</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/412091" id="412091">[RHEL5 U1] [ia64] Kernel test failing under limited memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414041" id="414041">NFS: System crashes trying to force umount a unresponsive, interruptible mount, which holds references to silly renamed files.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/424181" id="424181">RHEL5.1 beta: System hung during warm boot-cycling test</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425381" id="425381">CVE-2007-6416 [RHEL 5.2] [XEN/IA64] Security: vulnerability of copy_to_user in PAL emulation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426289" id="426289">[REG][5.1] VLAN add operation fail on s2io.ko driver(Neterion 10GbE card driver),</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427994" id="427994">CVE-2007-3104 Null pointer to an inode in a dentry can cause an oops in sysfs_readdir</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428791" id="428791">CVE-2008-0001 kernel: filesystem corruption by unprivileged user via directory truncation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089004" comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089002" comment="kernel is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089024" comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089022" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089008" comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089010" comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089016" comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089012" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089006" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089020" comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089018" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080089014" comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080090" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0090: icu security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0090-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0090.html" />
          <reference source="CVE" ref_id="CVE-2007-4770" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4770.html" />
          <reference source="CVE" ref_id="CVE-2007-4771" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4771.html" />
    
    <description>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

Will Drewry reported multiple flaws in the way libicu processed certain
malformed regular expressions. If an application linked against ICU, such
as OpenOffice.org, processed a carefully crafted regular expression, it may
be possible to execute arbitrary code as the user running the application.
(CVE-2007-4770, CVE-2007-4771)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-01-25" />
        <updated date="2008-01-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4770.html">CVE-2007-4770</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4771.html">CVE-2007-4771</cve>
                <bugzilla href="http://bugzilla.redhat.com/429023" id="429023">CVE-2007-4770 libicu poor back reference validation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429025" id="429025">CVE-2007-4771 libicu incomplete interval handling</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080090008" comment="libicu is earlier than 0:3.6-5.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080090009" comment="libicu is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080090006" comment="libicu-devel is earlier than 0:3.6-5.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080090007" comment="libicu-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080090004" comment="libicu-doc is earlier than 0:3.6-5.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080090005" comment="libicu-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080090002" comment="icu is earlier than 0:3.6-5.11.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080090003" comment="icu is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080100" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0100: java-1.4.2-bea security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0100.html" />
          <reference source="CVE" ref_id="CVE-2007-4381" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4381.html" />
          <reference source="CVE" ref_id="CVE-2007-2788" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2788.html" />
          <reference source="CVE" ref_id="CVE-2007-2789" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2789.html" />
          <reference source="CVE" ref_id="CVE-2007-3698" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3698.html" />
          <reference source="CVE" ref_id="CVE-2007-5232" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5232.html" />
          <reference source="CVE" ref_id="CVE-2007-5240" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5240.html" />
          <reference source="CVE" ref_id="CVE-2007-5273" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5273.html" />
          <reference source="CVE" ref_id="CVE-2007-5239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5239.html" />
    
    <description>The BEA WebLogic JRockit 1.4.2_16 JRE and SDK contains BEA WebLogic JRockit
Virtual Machine 1.4.2_16 and is certified for the Java 2 Platform, Standard
Edition, v1.4.2.

A buffer overflow in the Java Runtime Environment image handling code was
found. If an attacker could induce a server application to process a
specially crafted image file, the attacker could potentially cause a
denial-of-service or execute arbitrary code as the user running the Java
Virtual Machine. (CVE-2007-2788, CVE-2007-2789)

A denial of service flaw was found in the way the JSSE component processed
SSL/TLS handshake requests. A remote attacker able to connect to a JSSE
enabled service could send a specially crafted handshake which would cause
the Java Runtime Environment to stop responding to future requests.
(CVE-2007-3698)

A flaw was found in the way the Java Runtime Environment processed font
data. An applet viewed via the "appletviewer" application could elevate its
privileges, allowing the applet to perform actions with the same
permissions as the user running the "appletviewer" application. The same
flaw could, potentially, crash a server application which processed
untrusted font information from a third party. (CVE-2007-4381)

A flaw in the applet caching mechanism of the Java Runtime Environment
(JRE) did not correctly process the creation of network connections. A
remote attacker could use this flaw to create connections to services on
machines other than the one that the applet was downloaded from.
(CVE-2007-5232)

Untrusted Java Applets were able to drag and drop files to a desktop
application. A user-assisted remote attacker could use this flaw to move or
copy arbitrary files. (CVE-2007-5239)

The Java Runtime Environment (JRE) allowed untrusted Java Applets or
applications to display over-sized windows. This could be used by remote
attackers to hide security warning banners. (CVE-2007-5240)

Unsigned Java Applets communicating via a HTTP proxy could allow a remote
attacker to violate the Java security model. A cached, malicious Applet
could create network connections to services on other machines.
(CVE-2007-5273)

Please note: the vulnerabilities noted above concerned with applets can
only be triggered in java-1.4.2-bea by calling the "appletviewer"
application.

All users of java-1.4.2-bea should upgrade to these updated packages, which
contain the BEA WebLogic JRockit 1.4.2_16 release which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-11" />
        <updated date="2008-03-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4381.html">CVE-2007-4381</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2788.html">CVE-2007-2788</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2789.html">CVE-2007-2789</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3698.html">CVE-2007-3698</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5232.html">CVE-2007-5232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5240.html">CVE-2007-5240</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5273.html">CVE-2007-5273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5239.html">CVE-2007-5239</cve>
                <bugzilla href="http://bugzilla.redhat.com/249539" id="249539">CVE-2007-3698 Java Secure Socket Extension Does Not Correctly Process SSL/TLS Handshake Requests Resulting in a Denial of Service (DoS) Condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250725" id="250725">CVE-2007-2788 Integer overflow in the embedded ICC profile image parser in Sun Java Development Kit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250729" id="250729">CVE-2007-2789  BMP image parser vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253488" id="253488">CVE-2007-4381 java: Vulnerability in the font parsing code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321951" id="321951">CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321991" id="321991">CVE-2007-5240 Applets or Applications are allowed to display an oversized window</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324351" id="324351">CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080100004" comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100005" comment="java-1.4.2-bea-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080100002" comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100003" comment="java-1.4.2-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080100006" comment="java-1.4.2-bea-src is earlier than 0:1.4.2.16-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100007" comment="java-1.4.2-bea-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080100012" comment="java-1.4.2-bea-missioncontrol is earlier than 0:1.4.2.16-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100013" comment="java-1.4.2-bea-missioncontrol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080100010" comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100011" comment="java-1.4.2-bea-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080100008" comment="java-1.4.2-bea-demo is earlier than 0:1.4.2.16-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100009" comment="java-1.4.2-bea-demo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080103" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0103: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0103-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0103.html" />
          <reference source="CVE" ref_id="CVE-2008-0412" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0412.html" />
          <reference source="CVE" ref_id="CVE-2008-0413" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0413.html" />
          <reference source="CVE" ref_id="CVE-2008-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0415.html" />
          <reference source="CVE" ref_id="CVE-2008-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0416.html" />
          <reference source="CVE" ref_id="CVE-2008-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0417.html" />
          <reference source="CVE" ref_id="CVE-2008-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0418.html" />
          <reference source="CVE" ref_id="CVE-2008-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0419.html" />
          <reference source="CVE" ref_id="CVE-2008-0420" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0420.html" />
          <reference source="CVE" ref_id="CVE-2008-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0591.html" />
          <reference source="CVE" ref_id="CVE-2008-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0592.html" />
          <reference source="CVE" ref_id="CVE-2008-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0593.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the way Firefox processed certain malformed web
content. A webpage containing malicious content could cause Firefox to
crash, or potentially execute arbitrary code as the user running Firefox.
(CVE-2008-0412, CVE-2008-0413, CVE-2008-0415, CVE-2008-0419)

Several flaws were found in the way Firefox displayed malformed web
content. A webpage containing specially-crafted content could trick a user
into surrendering sensitive information. (CVE-2008-0591, CVE-2008-0593)

A flaw was found in the way Firefox stored password data. If a user saves
login information for a malicious website, it could be possible to corrupt
the password database, preventing the user from properly accessing saved
password data. (CVE-2008-0417)

A flaw was found in the way Firefox handles certain chrome URLs. If a user
has certain extensions installed, it could allow a malicious website to
steal sensitive session data. Note: this flaw does not affect a default
installation of Firefox. (CVE-2008-0418)

A flaw was found in the way Firefox saves certain text files. If a
website offers a file of type "plain/text", rather than "text/plain",
Firefox will not show future "text/plain" content to the user in the
browser, forcing them to save those files locally to view the content.
(CVE-2008-0592) 

Users of firefox are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0412.html">CVE-2008-0412</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0413.html">CVE-2008-0413</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0415.html">CVE-2008-0415</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0416.html">CVE-2008-0416</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0417.html">CVE-2008-0417</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0418.html">CVE-2008-0418</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0419.html">CVE-2008-0419</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0420.html">CVE-2008-0420</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0591.html">CVE-2008-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0592.html">CVE-2008-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0593.html">CVE-2008-0593</cve>
                <bugzilla href="http://bugzilla.redhat.com/431732" id="431732">CVE-2008-0412 Mozilla layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431733" id="431733">CVE-2008-0413 Mozilla javascript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431739" id="431739">CVE-2008-0415 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431742" id="431742">CVE-2008-0417 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431748" id="431748">CVE-2008-0418 Mozilla chrome: directory traversal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431749" id="431749">CVE-2008-0419 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431751" id="431751">CVE-2008-0591 Mozilla information disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431752" id="431752">CVE-2008-0592 Mozilla text file mishandling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431756" id="431756">CVE-2008-0593 Mozilla URL token stealing flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080103004" comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103005" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080103002" comment="firefox is earlier than 0:1.5.0.12-9.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103007" comment="firefox is earlier than 0:1.5.0.12-0.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080104" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0104: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0104-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0104.html" />
          <reference source="CVE" ref_id="CVE-2008-0304" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0304.html" />
          <reference source="CVE" ref_id="CVE-2008-0412" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0412.html" />
          <reference source="CVE" ref_id="CVE-2008-0413" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0413.html" />
          <reference source="CVE" ref_id="CVE-2008-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0415.html" />
          <reference source="CVE" ref_id="CVE-2008-0416" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0416.html" />
          <reference source="CVE" ref_id="CVE-2008-0417" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0417.html" />
          <reference source="CVE" ref_id="CVE-2008-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0418.html" />
          <reference source="CVE" ref_id="CVE-2008-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0419.html" />
          <reference source="CVE" ref_id="CVE-2008-0420" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0420.html" />
          <reference source="CVE" ref_id="CVE-2008-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0591.html" />
          <reference source="CVE" ref_id="CVE-2008-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0592.html" />
          <reference source="CVE" ref_id="CVE-2008-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0593.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the way SeaMonkey processed certain malformed
web content. A webpage containing malicious content could cause SeaMonkey
to crash, or potentially execute arbitrary code as the user running
SeaMonkey. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415, CVE-2008-0419)

Several flaws were found in the way SeaMonkey displayed malformed web
content. A webpage containing specially-crafted content could trick a user
into surrendering sensitive information. (CVE-2008-0591, CVE-2008-0593)

A flaw was found in the way SeaMonkey stored password data. If a user
saves login information for a malicious website, it could be possible
to corrupt the password database, preventing the user from properly
accessing saved password data. (CVE-2008-0417)

A flaw was found in the way SeaMonkey handles certain chrome URLs. If a
user has certain extensions installed, it could allow a malicious website
to steal sensitive session data. Note: this flaw does not affect a default
installation of SeaMonkey. (CVE-2008-0418)

A flaw was found in the way SeaMonkey saves certain text files. If a
website offers a file of type "plain/text", rather than "text/plain",
SeaMonkey will not show future "text/plain" content to the user in the
browser, forcing them to save those files locally to view the content.
(CVE-2008-0592)

Users of SeaMonkey are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-07" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0304.html">CVE-2008-0304</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0412.html">CVE-2008-0412</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0413.html">CVE-2008-0413</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0415.html">CVE-2008-0415</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0416.html">CVE-2008-0416</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0417.html">CVE-2008-0417</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0418.html">CVE-2008-0418</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0419.html">CVE-2008-0419</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0420.html">CVE-2008-0420</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0591.html">CVE-2008-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0592.html">CVE-2008-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0593.html">CVE-2008-0593</cve>
                <bugzilla href="http://bugzilla.redhat.com/431732" id="431732">CVE-2008-0412 Mozilla layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431733" id="431733">CVE-2008-0413 Mozilla javascript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431739" id="431739">CVE-2008-0415 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431742" id="431742">CVE-2008-0417 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431748" id="431748">CVE-2008-0418 Mozilla chrome: directory traversal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431749" id="431749">CVE-2008-0419 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431751" id="431751">CVE-2008-0591 Mozilla information disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431752" id="431752">CVE-2008-0592 Mozilla text file mishandling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431756" id="431756">CVE-2008-0593 Mozilla URL token stealing flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104006" comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104010" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104008" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104018" comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104002" comment="seamonkey is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104016" comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104014" comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104012" comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104004" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104020" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104025" comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104030" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104026" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104029" comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104023" comment="seamonkey is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104032" comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104031" comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104028" comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104027" comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080104024" comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080105" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0105: thunderbird security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0105-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0105.html" />
          <reference source="CVE" ref_id="CVE-2008-0304" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0304.html" />
          <reference source="CVE" ref_id="CVE-2008-0412" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0412.html" />
          <reference source="CVE" ref_id="CVE-2008-0413" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0413.html" />
          <reference source="CVE" ref_id="CVE-2008-0415" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0415.html" />
          <reference source="CVE" ref_id="CVE-2008-0418" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0418.html" />
          <reference source="CVE" ref_id="CVE-2008-0419" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0419.html" />
          <reference source="CVE" ref_id="CVE-2008-0420" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0420.html" />
          <reference source="CVE" ref_id="CVE-2008-0591" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0591.html" />
          <reference source="CVE" ref_id="CVE-2008-0592" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0592.html" />
          <reference source="CVE" ref_id="CVE-2008-0593" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0593.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A heap-based buffer overflow flaw was found in the way Thunderbird
processed messages with external-body Multipurpose Internet Message
Extensions (MIME) types. A HTML mail message containing malicious content
could cause Thunderbird to execute arbitrary code as the user running
Thunderbird. (CVE-2008-0304)

Several flaws were found in the way Thunderbird processed certain malformed
HTML mail content. A HTML mail message containing malicious content could
cause Thunderbird to crash, or potentially execute arbitrary code as the
user running Thunderbird. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415,
CVE-2008-0419)

Several flaws were found in the way Thunderbird displayed malformed HTML
mail content. A HTML mail message containing specially-crafted content
could trick a user into surrendering sensitive information. (CVE-2008-0420,
CVE-2008-0591, CVE-2008-0593)

A flaw was found in the way Thunderbird handles certain chrome URLs. If a
user has certain extensions installed, it could allow a malicious HTML mail
message to steal sensitive session data. Note: this flaw does not affect a
default installation of Thunderbird. (CVE-2008-0418)

Note: JavaScript support is disabled by default in Thunderbird; the above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the way Thunderbird saves certain text files. If a
remote site offers a file of type "plain/text", rather than "text/plain",
Thunderbird will not show future "text/plain" content to the user, forcing
them to save those files locally to view the content. (CVE-2008-0592)

Users of thunderbird are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-07" />
        <updated date="2008-02-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0304.html">CVE-2008-0304</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0412.html">CVE-2008-0412</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0413.html">CVE-2008-0413</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0415.html">CVE-2008-0415</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0418.html">CVE-2008-0418</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0419.html">CVE-2008-0419</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0420.html">CVE-2008-0420</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0591.html">CVE-2008-0591</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0592.html">CVE-2008-0592</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0593.html">CVE-2008-0593</cve>
                <bugzilla href="http://bugzilla.redhat.com/431732" id="431732">CVE-2008-0412 Mozilla layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431733" id="431733">CVE-2008-0413 Mozilla javascript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431739" id="431739">CVE-2008-0415 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431748" id="431748">CVE-2008-0418 Mozilla chrome: directory traversal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431749" id="431749">CVE-2008-0419 Mozilla arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431751" id="431751">CVE-2008-0591 Mozilla information disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431752" id="431752">CVE-2008-0592 Mozilla text file mishandling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431756" id="431756">CVE-2008-0593 Mozilla URL token stealing flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435123" id="435123">CVE-2008-0304 thunderbird/seamonkey: MIME External-Body Heap Overflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105002" comment="thunderbird is earlier than 0:1.5.0.12-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105005" comment="thunderbird is earlier than 0:1.5.0.12-8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080110" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0110: openldap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0110-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0110.html" />
          <reference source="CVE" ref_id="CVE-2007-6698" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6698.html" />
          <reference source="CVE" ref_id="CVE-2008-0658" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0658.html" />
    
    <description>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols for
accessing directory services.

These updated openldap packages fix a flaw in the way the OpenLDAP slapd
daemon handled modify and modrdn requests with NOOP control on objects
stored in a Berkeley DB (BDB) storage backend.  An authenticated attacker
with permission to perform modify or modrdn operations on such LDAP objects
could cause slapd to crash. (CVE-2007-6698, CVE-2008-0658)

Users of openldap should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-21" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6698.html">CVE-2007-6698</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0658.html">CVE-2008-0658</cve>
                <bugzilla href="http://bugzilla.redhat.com/431203" id="431203">CVE-2007-6698 openldap: slapd crash on NOOP control operation on entry in bdb storage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432008" id="432008">CVE-2008-0658 openldap: slapd crash on modrdn operation with NOOP control on entry in bdb storage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110010" comment="openldap-devel is earlier than 0:2.3.27-8.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110011" comment="openldap-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110004" comment="openldap-clients is earlier than 0:2.3.27-8.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110005" comment="openldap-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110006" comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110007" comment="openldap-servers-sql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110008" comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110009" comment="compat-openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110002" comment="openldap is earlier than 0:2.3.27-8.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110003" comment="openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110012" comment="openldap-servers is earlier than 0:2.3.27-8.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110013" comment="openldap-servers is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110023" comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110024" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110019" comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110020" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110021" comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110022" comment="openldap-servers-sql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110017" comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110018" comment="compat-openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110015" comment="openldap is earlier than 0:2.2.13-8.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110016" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080110025" comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110026" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080123" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0123: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0123-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0123.html" />
          <reference source="CVE" ref_id="CVE-2008-0657" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0657.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language.

These updated java-1.5.0-sun packages resolve the following security issues:

Two vulnerabilities in the Java Runtime Environment allowed an untrusted
application or applet to elevate the assigned privileges. This could be
misused by a malicious website to read and write local files or execute
local applications in the context of the user running the Java process.
(CVE-2008-0657) 

Users of java-1.5.0-sun should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-12" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0657.html">CVE-2008-0657</cve>
                <bugzilla href="http://bugzilla.redhat.com/431861" id="431861">CVE-2008-0657 java-1.5.0 Privilege escalation via unstrusted applet and application</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080123012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080123002" comment="java-1.5.0-sun is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080123010" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123011" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080123006" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080123008" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123009" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080123004" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123005" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080129" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0129: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0129-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0129.html" />
          <reference source="CVE" ref_id="CVE-2008-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0600.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

A flaw was found in vmsplice. An unprivileged local user could use this
flaw to gain root privileges. (CVE-2008-0600)

Red Hat is aware that a public exploit for this issue is available. This
issue did not affect the Linux kernels distributed with Red Hat Enterprise
Linux 2.1, 3, or 4.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-12" />
        <updated date="2008-02-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0600.html">CVE-2008-0600</cve>
                <bugzilla href="http://bugzilla.redhat.com/432251" id="432251">CVE-2008-0600 kernel vmsplice_to_pipe flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129004" comment="kernel-headers is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129002" comment="kernel is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129024" comment="kernel-doc is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129022" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129006" comment="kernel-devel is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129014" comment="kernel-debug is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129016" comment="kernel-kdump is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129012" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129008" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129020" comment="kernel-PAE is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129018" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080129010" comment="kernel-xen is earlier than 0:2.6.18-53.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080131" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0131: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0131-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0131.html" />
          <reference source="CVE" ref_id="CVE-2008-0554" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0554.html" />
    
    <description>The netpbm package contains a library of functions for editing and
converting between various graphics file formats, including .pbm (portable
bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable
pixmaps) and others. The package includes no interactive tools and is
primarily used by other programs (eg CGI scripts that manage web-site
images).

An input validation flaw was discovered in the GIF-to-PNM converter
(giftopnm) shipped with the netpbm package. An attacker could create a
carefully crafted GIF file which could cause giftopnm to crash or possibly
execute arbitrary code as the user running giftopnm. (CVE-2008-0554)

All users are advised to upgrade to these updated packages which contain a
backported patch which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-28" />
        <updated date="2008-02-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0554.html">CVE-2008-0554</cve>
                <bugzilla href="http://bugzilla.redhat.com/431525" id="431525">CVE-2008-0554 netpbm: GIF handling buffer overflow in giftopnm</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080131002" comment="netpbm is earlier than 0:9.24-11.30.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080131003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080131004" comment="netpbm-devel is earlier than 0:9.24-11.30.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080131005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080131006" comment="netpbm-progs is earlier than 0:9.24-11.30.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080131007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080131009" comment="netpbm is earlier than 0:10.25-2.EL4.6.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080131003" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080131010" comment="netpbm-devel is earlier than 0:10.25-2.EL4.6.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080131005" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080131011" comment="netpbm-progs is earlier than 0:10.25-2.EL4.6.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080131007" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080132" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0132: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0132.html" />
          <reference source="CVE" ref_id="CVE-2007-3698" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3698.html" />
          <reference source="CVE" ref_id="CVE-2007-4381" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4381.html" />
          <reference source="CVE" ref_id="CVE-2007-5232" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5232.html" />
          <reference source="CVE" ref_id="CVE-2007-5238" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5238.html" />
          <reference source="CVE" ref_id="CVE-2007-5239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5239.html" />
          <reference source="CVE" ref_id="CVE-2007-5240" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5240.html" />
          <reference source="CVE" ref_id="CVE-2007-5273" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5273.html" />
          <reference source="CVE" ref_id="CVE-2007-5274" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5274.html" />
          <reference source="CVE" ref_id="CVE-2008-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1189.html" />
          <reference source="CVE" ref_id="CVE-2008-1190" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1190.html" />
          <reference source="CVE" ref_id="CVE-2008-1192" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1192.html" />
          <reference source="CVE" ref_id="CVE-2008-1195" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1195.html" />
    
    <description>IBM's 1.4.2 SR10 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

The Java Secure Socket Extension (JSSE) component did not correctly process
SSL/TLS handshake requests. A remote attacker who is able to connect to a
JSSE-based service could trigger this flaw leading to a denial-of-service.
(CVE-2007-3698) 

A flaw was found in the way the Java Runtime Environment processes font
data. An untrusted applet could elevate its privileges, allowing the applet
to perform actions with the same permissions as the logged in user. It may
also be possible to crash a server application which processes untrusted
font information from a third party. (CVE-2007-4381) 

The applet caching mechanism of the Java Runtime Environment (JRE) did not
correctly process the creation of network connections. A remote attacker
could use this flaw to create connections to services on machines other
than the one that the applet was downloaded from. (CVE-2007-5232)

Multiple vulnerabilities existed in Java Web Start allowing an untrusted
application to determine the location of the Java Web Start cache.
(CVE-2007-5238)

Untrusted Java Web Start Applications or Java Applets were able to drag and
drop a file to a Desktop Application. A user-assisted remote attacker could
use this flaw to move or copy arbitrary files. (CVE-2007-5239)

The Java Runtime Environment allowed untrusted Java Applets or applications
to display oversized Windows. This could be used by remote attackers to
hide security warning banners. (CVE-2007-5240)

Unsigned Java Applets communicating via a HTTP proxy could allow a remote
attacker to violate the Java security model. A cached malicious Applet
could create network connections to services on other machines.
(CVE-2007-5273)

Unsigned Applets loaded with Mozilla Firefox or Opera browsers allowed
remote attackers to violate the Java security model. A cached malicious
Applet could create network connections to services on other machines.
(CVE-2007-5274)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, that contain IBM's 1.4.2 SR10 Java release which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-14" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3698.html">CVE-2007-3698</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4381.html">CVE-2007-4381</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5232.html">CVE-2007-5232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5238.html">CVE-2007-5238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5239.html">CVE-2007-5239</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5240.html">CVE-2007-5240</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5273.html">CVE-2007-5273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5274.html">CVE-2007-5274</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1189.html">CVE-2008-1189</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1190.html">CVE-2008-1190</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1192.html">CVE-2008-1192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1195.html">CVE-2008-1195</cve>
                <bugzilla href="http://bugzilla.redhat.com/249539" id="249539">CVE-2007-3698 Java Secure Socket Extension Does Not Correctly Process SSL/TLS Handshake Requests Resulting in a Denial of Service (DoS) Condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253488" id="253488">CVE-2007-4381 java: Vulnerability in the font parsing code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321951" id="321951">CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321961" id="321961">CVE-2007-5238  Vulnerabilities in Java Web Start allow to determine the location of the Java Web Start cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321981" id="321981">CVE-2007-5239 Untrusted Application or Applet May Move or Copy Arbitrary Files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321991" id="321991">CVE-2007-5240 Applets or Applications are allowed to display an oversized window</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324351" id="324351">CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324361" id="324361">CVE-2007-5274 Anti-DNS Pinning and Java Applets with Opera and Firefox</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132006" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132010" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132008" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132009" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080132012" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132013" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080134" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0134: tcltk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0134-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0134.html" />
          <reference source="CVE" ref_id="CVE-2008-0553" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0553.html" />
          <reference source="CVE" ref_id="CVE-2007-5378" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5378.html" />
          <reference source="CVE" ref_id="CVE-2007-4772" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4772.html" />
    
    <description>Tcl is a scripting language designed for embedding into other applications
and for use with Tk, a widget set.

An input validation flaw was discovered in Tk's GIF image handling. A
code-size value read from a GIF image was not properly validated before
being used, leading to a buffer overflow. A specially crafted GIF file
could use this to cause a crash or, potentially, execute code with the
privileges of the application using the Tk graphical toolkit.
(CVE-2008-0553)

A buffer overflow flaw was discovered in Tk's animated GIF image handling.
An animated GIF containing an initial image smaller than subsequent images
could cause a crash or, potentially, execute code with the privileges of
the application using the Tk library. (CVE-2007-5378)

A flaw in the Tcl regular expression handling engine was discovered by Will
Drewry. This flaw, first discovered in the Tcl regular expression engine
used in the PostgreSQL database server, resulted in an infinite loop when
processing certain regular expressions. (CVE-2007-4772)

All users are advised to upgrade to these updated packages which contain
backported patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-21" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0553.html">CVE-2008-0553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5378.html">CVE-2007-5378</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4772.html">CVE-2007-4772</cve>
                <bugzilla href="http://bugzilla.redhat.com/316511" id="316511">CVE-2007-4772 postgresql DoS via infinite loop in regex NFA optimization code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/332021" id="332021">CVE-2007-5378 Tk GIF processing buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431518" id="431518">CVE-2008-0553 tk: GIF handling buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134020" comment="tcl-devel is earlier than 0:8.3.5-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134021" comment="tcl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134008" comment="tk is earlier than 0:8.3.5-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134009" comment="tk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134002" comment="tcltk is earlier than 0:8.3.5-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134003" comment="tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134018" comment="tix is earlier than 0:8.1.4-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134019" comment="tix is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134014" comment="expect is earlier than 0:5.38.0-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134015" comment="expect is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134016" comment="tcl-html is earlier than 0:8.3.5-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134017" comment="tcl-html is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134004" comment="tclx is earlier than 0:8.3-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134005" comment="tclx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134026" comment="tk-devel is earlier than 0:8.3.5-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134027" comment="tk-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134024" comment="expectk is earlier than 0:5.38.0-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134025" comment="expectk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134006" comment="tcl is earlier than 0:8.3.5-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134007" comment="tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134022" comment="tcllib is earlier than 0:1.3-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134023" comment="tcllib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134010" comment="expect-devel is earlier than 0:5.38.0-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134011" comment="expect-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080134012" comment="itcl is earlier than 0:3.2-92.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134013" comment="itcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080135" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0135: tk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0135-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0135.html" />
          <reference source="CVE" ref_id="CVE-2008-0553" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0553.html" />
          <reference source="CVE" ref_id="CVE-2007-5378" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5378.html" />
    
    <description>Tk is a graphical toolkit for the Tcl scripting language.

An input validation flaw was discovered in Tk's GIF image handling. A
code-size value read from a GIF image was not properly validated before
being used, leading to a buffer overflow. A specially crafted GIF file
could use this to cause a crash or, potentially, execute code with the
privileges of the application using the Tk graphical toolkit.
(CVE-2008-0553)

A buffer overflow flaw was discovered in Tk's animated GIF image handling.
An animated GIF containing an initial image smaller than subsequent images
could cause a crash or, potentially, execute code with the privileges of
the application using the Tk library. (CVE-2007-5378)

All users are advised to upgrade to these updated packages which contain a
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-21" />
        <updated date="2008-02-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0553.html">CVE-2008-0553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5378.html">CVE-2007-5378</cve>
                <bugzilla href="http://bugzilla.redhat.com/332021" id="332021">CVE-2007-5378 Tk GIF processing buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431518" id="431518">CVE-2008-0553 tk: GIF handling buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080135002" comment="tk is earlier than 0:8.4.7-3.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134009" comment="tk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080135004" comment="tk-devel is earlier than 0:8.4.7-3.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080134027" comment="tk-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080136" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0136: tk security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0136-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0136.html" />
          <reference source="CVE" ref_id="CVE-2008-0553" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0553.html" />
          <reference source="CVE" ref_id="CVE-2007-5137" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5137.html" />
    
    <description>Tk is a graphical toolkit for the Tcl scripting language.

An input validation flaw was discovered in Tk's GIF image handling. A
code-size value read from a GIF image was not properly validated before
being used, leading to a buffer overflow. A specially crafted GIF file
could use this to cause a crash or, potentially, execute code with the
privileges of the application using the Tk graphical toolkit.
(CVE-2008-0553)

A buffer overflow flaw was discovered in Tk's animated GIF image handling.
An animated GIF containing an initial image smaller than subsequent images
could cause a crash or, potentially, execute code with the privileges of
the application using the Tk library. (CVE-2007-5137)

All users are advised to upgrade to these updated packages which contain a
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-21" />
        <updated date="2008-02-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0553.html">CVE-2008-0553</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5137.html">CVE-2007-5137</cve>
                <bugzilla href="http://bugzilla.redhat.com/290991" id="290991">CVE-2007-5137 Tk GIF processing buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431518" id="431518">CVE-2008-0553 tk: GIF handling buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080136002" comment="tk is earlier than 0:8.4.13-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080136003" comment="tk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080136004" comment="tk-devel is earlier than 0:8.4.13-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080136005" comment="tk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080144" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0144: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0144-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0144.html" />
          <reference source="CVE" ref_id="CVE-2007-5659" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5659.html" />
          <reference source="CVE" ref_id="CVE-2007-5663" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5663.html" />
          <reference source="CVE" ref_id="CVE-2007-5666" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5666.html" />
          <reference source="CVE" ref_id="CVE-2007-0044" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0044.html" />
          <reference source="CVE" ref_id="CVE-2008-0655" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0655.html" />
          <reference source="CVE" ref_id="CVE-2008-0667" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0667.html" />
          <reference source="CVE" ref_id="CVE-2008-0726" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0726.html" />
    
    <description>The Adobe Reader allows users to view and print documents in portable
document format (PDF).

Several flaws were found in the way Adobe Reader processed malformed PDF
files. An attacker could create a malicious PDF file which could execute
arbitrary code if opened by a victim. (CVE-2007-5659, CVE-2007-5663,
CVE-2007-5666, CVE-2008-0726)

A flaw was found in the way the Adobe Reader browser plug-in honored
certain requests. A malicious PDF file could cause the browser to request
an unauthorized URL, allowing for a cross-site request forgery attack.
(CVE-2007-0044)

A flaw was found in Adobe Reader's JavaScript API DOC.print function. A
malicious PDF file could silently trigger non-interactive printing of the
document, causing multiple copies to be printed without the users consent.
(CVE-2008-0667)

Additionally, this update fixes multiple unknown flaws in Adobe Reader.
When the information regarding these flaws is made public by Adobe, it will
be added to this advisory. (CVE-2008-0655)

Note: Adobe have yet to release security fixed versions of Adobe 7. All
users of Adobe Reader are, therefore, advised to install these updated
packages. They contain Adobe Reader version 8.1.2, which is not vulnerable
to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-22" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5659.html">CVE-2007-5659</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5663.html">CVE-2007-5663</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5666.html">CVE-2007-5666</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0044.html">CVE-2007-0044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0655.html">CVE-2008-0655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0667.html">CVE-2008-0667</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0726.html">CVE-2008-0726</cve>
                <bugzilla href="http://bugzilla.redhat.com/223113" id="223113">CVE-2007-0044 Acrobat Reader Universal CSRF and session riding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431985" id="431985">CVE-2008-0655 acroread: unspecified vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432471" id="432471">CVE-2008-0667 acroread: silent print vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432629" id="432629">CVE-2007-5659 acroread Multiple buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432630" id="432630">CVE-2007-5663 acroread JavaScript Insecure Method Exposure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432632" id="432632">CVE-2007-5666 acroread JavaScript Insecure Libary Search Path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432757" id="432757">CVE-2008-0726 Acroread memory corruption</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080144004" comment="acroread-plugin is earlier than 0:8.1.2-1.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080144005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080144002" comment="acroread is earlier than 0:8.1.2-1.el5.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080144003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080145" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0145: ImageMagick security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0145-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0145.html" />
          <reference source="CVE" ref_id="CVE-2007-1797" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1797.html" />
          <reference source="CVE" ref_id="CVE-2007-4985" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4985.html" />
          <reference source="CVE" ref_id="CVE-2007-4986" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4986.html" />
          <reference source="CVE" ref_id="CVE-2007-4988" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4988.html" />
          <reference source="CVE" ref_id="CVE-2008-1096" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1096.html" />
          <reference source="CVE" ref_id="CVE-2008-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1097.html" />
    
    <description>ImageMagick is an image display and manipulation tool for the X Window
System that can read and write multiple image formats.

Several heap-based buffer overflow flaws were found in ImageMagick. If a
victim opened a specially crafted DCM or XWD file, an attacker could
potentially execute arbitrary code on the victim's machine. (CVE-2007-1797)

Several denial of service flaws were found in ImageMagick's parsing of XCF
and DCM files. Attempting to process a specially-crafted input file in
these formats could cause ImageMagick to enter an infinite loop.
(CVE-2007-4985)

Several integer overflow flaws were found in ImageMagick. If a victim
opened a specially-crafted DCM, DIB, XBM, XCF or XWD file, an attacker
could potentially execute arbitrary code with the privileges of the user
running ImageMagick. (CVE-2007-4986)

An integer overflow flaw was found in ImageMagick's DIB parsing code. If a
victim opened a specially-crafted DIB file, an attacker could potentially
execute arbitrary code with the privileges of the user running ImageMagick.
(CVE-2007-4988)

A heap-based buffer overflow flaw was found in the way ImageMagick parsed
XCF files. If a specially-crafted XCF image was opened, ImageMagick could
be made to overwrite heap memory beyond the bounds of its allocated memory.
This could, potentially, allow an attacker to execute arbitrary code on the
machine running ImageMagick. (CVE-2008-1096)

A heap-based buffer overflow flaw was found in ImageMagick's processing of
certain malformed PCX images. If a victim opened a specially-crafted PCX
file, an attacker could possibly execute arbitrary code on the victim's
machine. (CVE-2008-1097)

All users of ImageMagick should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-16" />
        <updated date="2008-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1797.html">CVE-2007-1797</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4985.html">CVE-2007-4985</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4986.html">CVE-2007-4986</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4988.html">CVE-2007-4988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1096.html">CVE-2008-1096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1097.html">CVE-2008-1097</cve>
                <bugzilla href="http://bugzilla.redhat.com/235071" id="235071">CVE-2007-1797 Heap overflow in ImageMagick's DCM and XWD coders</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/285861" id="285861">CVE-2008-1097 Memory corruption in ImageMagick's PCX coder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/286411" id="286411">CVE-2008-1096 Out of bound write in ImageMagick's XCF coder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/310081" id="310081">CVE-2007-4988 Integer overflow in ImageMagick's DIB coder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/310091" id="310091">CVE-2007-4985 Infinite loops in ImageMagick's XCF and DCM coders</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/310121" id="310121">CVE-2007-4986 Multiple integer overflows in ImageMagick</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145006" comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145007" comment="ImageMagick-c++-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145004" comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145005" comment="ImageMagick-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145010" comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145011" comment="ImageMagick-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145002" comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145003" comment="ImageMagick is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145008" comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145009" comment="ImageMagick-c++ is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145021" comment="ImageMagick-devel is earlier than 0:5.5.6-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145022" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145019" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145020" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145017" comment="ImageMagick-perl is earlier than 0:5.5.6-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145018" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145013" comment="ImageMagick is earlier than 0:5.5.6-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145014" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145015" comment="ImageMagick-c++ is earlier than 0:5.5.6-28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145016" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145027" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145020" comment="ImageMagick-c++-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145026" comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145022" comment="ImageMagick-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145028" comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145018" comment="ImageMagick-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145024" comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145014" comment="ImageMagick is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080145025" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080145016" comment="ImageMagick-c++ is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080146" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0146: gd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0146-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0146.html" />
          <reference source="CVE" ref_id="CVE-2006-4484" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4484.html" />
          <reference source="CVE" ref_id="CVE-2007-0455" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0455.html" />
          <reference source="CVE" ref_id="CVE-2007-2756" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2756.html" />
          <reference source="CVE" ref_id="CVE-2007-3472" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3472.html" />
          <reference source="CVE" ref_id="CVE-2007-3473" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3473.html" />
          <reference source="CVE" ref_id="CVE-2007-3475" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3475.html" />
          <reference source="CVE" ref_id="CVE-2007-3476" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3476.html" />
    
    <description>The gd package contains a graphics library used for the dynamic creation of
images such as PNG and JPEG.

Multiple issues were discovered in the gd GIF image-handling code. A
carefully-crafted GIF file could cause a crash or possibly execute code
with the privileges of the application using the gd library.
(CVE-2006-4484, CVE-2007-3475, CVE-2007-3476)

An integer overflow was discovered in the gdImageCreateTrueColor()
function, leading to incorrect memory allocations. A carefully crafted
image could cause a crash or possibly execute code with the privileges of
the application using the gd library. (CVE-2007-3472)

A buffer over-read flaw was discovered. This could cause a crash in an
application using the gd library to render certain strings using a
JIS-encoded font. (CVE-2007-0455)

A flaw was discovered in the gd PNG image handling code. A truncated PNG
image could cause an infinite loop in an application using the gd library.
(CVE-2007-2756)

A flaw was discovered in the gd X BitMap (XBM) image-handling code. A
malformed or truncated XBM image could cause a crash in an application
using the gd library. (CVE-2007-3473)

Users of gd should upgrade to these updated packages, which contain
backported patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-28" />
        <updated date="2008-02-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4484.html">CVE-2006-4484</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0455.html">CVE-2007-0455</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2756.html">CVE-2007-2756</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3472.html">CVE-2007-3472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3473.html">CVE-2007-3473</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3475.html">CVE-2007-3475</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3476.html">CVE-2007-3476</cve>
                <bugzilla href="http://bugzilla.redhat.com/224607" id="224607">CVE-2007-0455 gd buffer overrun</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242033" id="242033">CVE-2007-2756 gd / php-gd ImageCreateFromPng infinite loop caused by truncated PNG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/276751" id="276751">CVE-2007-3472 libgd Integer overflow in TrueColor code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/276791" id="276791">CVE-2007-3473 libgd NULL pointer dereference when reading a corrupt X bitmap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/277181" id="277181">CVE-2007-3475 libgd Denial of service by GIF images without a global color map</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/277201" id="277201">CVE-2007-3476 libgd Denial of service by corrupted GIF images</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431568" id="431568">CVE-2006-4484 gd: GIF handling buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080146004" comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080146005" comment="gd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080146006" comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080146007" comment="gd-progs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080146002" comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080146003" comment="gd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080146013" comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080146014" comment="gd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080146011" comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080146012" comment="gd-progs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080146009" comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080146010" comment="gd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080153" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0153: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0153-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0153.html" />
          <reference source="CVE" ref_id="CVE-2008-0596" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0596.html" />
          <reference source="CVE" ref_id="CVE-2008-0597" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0597.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A flaw was found in the way CUPS handled the addition and removal of remote
shared printers via IPP.  A remote attacker could send malicious UDP IPP
packets causing the CUPS daemon to attempt to dereference already freed
memory and crash. (CVE-2008-0597)

A memory management flaw was found in the way CUPS handled the addition and
removal of remote shared printers via IPP.  When shared printer was
removed, allocated memory was not properly freed, leading to a memory leak
possibly causing CUPS daemon crash after exhausting available memory.
(CVE-2008-0596)

These issues were found during the investigation of CVE-2008-0882, which
did not affect Red Hat Enterprise Linux 3. 

Note that the default configuration of CUPS on Red Hat Enterprise Linux
3 allow requests of this type only from the local subnet.

In addition, these updated cups packages fix a bug that occurred when using
the CUPS polling daemon. Excessive debugging log information was saved to
the error_log file regardless of the LogLevel setting, which filled up disk
space rapidly.

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-25" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0596.html">CVE-2008-0596</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0597.html">CVE-2008-0597</cve>
                <bugzilla href="http://bugzilla.redhat.com/246545" id="246545">Cups fills up logfiles if queue is turned on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433825" id="433825">CVE-2008-0596 cups: memory leak handling IPP browse requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433847" id="433847">CVE-2008-0597 cups: dereference of free'd memory handling IPP browse requests</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080153004" comment="cups-devel is earlier than 1:1.1.17-13.3.51" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080153006" comment="cups-libs is earlier than 1:1.1.17-13.3.51" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080153002" comment="cups is earlier than 1:1.1.17-13.3.51" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080154" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0154: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0154-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0154.html" />
          <reference source="CVE" ref_id="CVE-2006-6921" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6921.html" />
          <reference source="CVE" ref_id="CVE-2007-5938" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5938.html" />
          <reference source="CVE" ref_id="CVE-2007-6063" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6063.html" />
          <reference source="CVE" ref_id="CVE-2007-6207" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6207.html" />
          <reference source="CVE" ref_id="CVE-2007-6694" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6694.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw in the hypervisor for hosts running on Itanium architectures
allowed an Intel VTi domain to read arbitrary physical memory from other
Intel VTi domains, which could make information available to unauthorized
users. (CVE-2007-6207, Important)

* two buffer overflow flaws were found in ISDN subsystem. A local
unprivileged user could use these flaws to cause a denial of service.
(CVE-2007-5938: Important, CVE-2007-6063: Moderate)

* a possible NULL pointer dereference was found in the subsystem used for
showing CPU information, as used by CHRP systems on PowerPC architectures.
This may have allowed a local unprivileged user to cause a denial of
service (crash). (CVE-2007-6694, Moderate)

* a flaw was found in the handling of zombie processes. A local user could
create processes that would not be properly reaped, possibly causing a
denial of service. (CVE-2006-6921, Moderate)

As well, these updated packages fix the following bugs:

* a bug was found in the Linux kernel audit subsystem. When the audit
daemon was setup to log the execve system call with a large number of
arguments, the kernel could run out of memory, causing a kernel panic.

* on IBM System z architectures, using the IBM Hardware Management Console
to toggle IBM FICON channel path ids (CHPID) caused a file ID miscompare,
possibly causing data corruption.

* when running the IA-32 Execution Layer (IA-32EL) or a Java VM on Itanium
architectures, a bug in the address translation in the hypervisor caused
the wrong address to be registered, causing Dom0 to hang.

* on Itanium architectures, frequent Corrected Platform Error errors may
have caused the hypervisor to hang.

* when enabling a CPU without hot plug support, routines for checking the
presence of the CPU were missing. The CPU tried to access its own
resources, causing a kernel panic.

* after updating to kernel-2.6.18-53.el5, a bug in the CCISS driver caused
the HP Array Configuration Utility CLI to become unstable, possibly causing
a system hang, or a kernel panic.

* a bug in NFS directory caching could have caused different hosts to have
different views of NFS directories.

* on Itanium architectures, the Corrected Machine Check Interrupt masked
hot-added CPUs as disabled.

* when running Oracle database software on the Intel 64 and AMD64
architectures, if an SGA larger than 4GB was created, and had hugepages
allocated to it, the hugepages were not freed after database shutdown.

* in a clustered environment, when two or more NFS clients had the same
logical volume mounted, and one of them modified a file on the volume, NULL
characters may have been inserted, possibly causing data corruption.

These updated packages resolve several severe issues in the lpfc driver:

* a system hang after LUN discovery.

* a general fault protection, a NULL pointer dereference, or slab
corruption could occur while running a debug on the kernel.

* the inability to handle kernel paging requests in "lpfc_get_scsi_buf".

* erroneous structure references caused certain FC discovery routines to
reference and change "lpfc_nodelist" structures, even after they were
freed.

* the lpfc driver failed to interpret certain fields correctly, causing
tape backup software to fail. Tape drives reported "Illegal Request".

* the lpfc driver did not clear structures correctly, resulting in SCSI
I/Os being rejected by targets, and causing errors.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-05" />
        <updated date="2008-03-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6921.html">CVE-2006-6921</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5938.html">CVE-2007-5938</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6063.html">CVE-2007-6063</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6207.html">CVE-2007-6207</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6694.html">CVE-2007-6694</cve>
                <bugzilla href="http://bugzilla.redhat.com/302921" id="302921">CVE-2006-6921 kernel: denial of service with wedged processes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/310651" id="310651">audit: Logging execve arguments, out of memory in audit_expand (kernel panic)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/385861" id="385861">CVE-2007-5938 NULL dereference in iwl driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/392101" id="392101">CVE-2007-6063 Linux Kernel isdn_net_setcfg buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396751" id="396751">CVE-2007-6694 /proc/cpuinfo DoS on some ppc machines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/402911" id="402911">LTC39906-[BBDQ] FICON DS8000: File ID Miscompare after CHPID off via HMC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/406881" id="406881">CVE-2007-6207 [5.2][XEN] Security: some HVM domain can access another domain memory.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/424191" id="424191">[Xen][5.1.z] Running IA32EL or java-vm causes dom0 hung</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/424271" id="424271">Severe issues in 5.1 lpfc driver: Request update to 8.1.10.12</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428290" id="428290">[Xen ia64] hypervisor sometimes hangs on Corrected Platform Errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429108" id="429108">[5.1] Panic if user enable a cpu which is not prepared for hotplug.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429515" id="429515">scsi: cciss - incompatability between hpacucli and RHEL 5.1 Kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429539" id="429539">NFS: Fix directory caching problem - with test case and patch.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430632" id="430632">CMCI is left disabled on hot-added processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431522" id="431522">RHEL 5.1 regression in hugepages due to pagetable sharing patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432078" id="432078">Null bytes in files access by 2 or more NFS clients</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154004" comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154002" comment="kernel is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154024" comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154022" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154006" comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154012" comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154016" comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154008" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154014" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154020" comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154018" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080154010" comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080155" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0155: ghostscript security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0155-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0155.html" />
          <reference source="CVE" ref_id="CVE-2008-0411" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0411.html" />
    
    <description>Ghostscript is a program for displaying PostScript files, or printing them
to non-PostScript printers.

Chris Evans from the Google Security Team reported a stack-based buffer
overflow flaw in Ghostscript's zseticcspace() function. An attacker could
create a malicious PostScript file that would cause Ghostscript to execute
arbitrary code when opened. (CVE-2008-0411)

These updated packages also fix a bug, which prevented the pxlmono printer
driver from producing valid output on Red Hat Enterprise Linux 4.

All users of ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-27" />
        <updated date="2008-03-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0411.html">CVE-2008-0411</cve>
                <bugzilla href="http://bugzilla.redhat.com/431536" id="431536">CVE-2008-0411 ghostscript: stack-based buffer overflow in .seticcspace operator</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155006" comment="ghostscript-gtk is earlier than 0:8.15.2-9.1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155007" comment="ghostscript-gtk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155002" comment="ghostscript is earlier than 0:8.15.2-9.1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155003" comment="ghostscript is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155004" comment="ghostscript-devel is earlier than 0:8.15.2-9.1.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155005" comment="ghostscript-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155009" comment="ghostscript is earlier than 0:7.05-32.1.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155010" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155011" comment="ghostscript-devel is earlier than 0:7.05-32.1.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155012" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155013" comment="hpijs is earlier than 0:1.3-32.1.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155014" comment="hpijs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155017" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155018" comment="ghostscript-gtk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155016" comment="ghostscript is earlier than 0:7.07-33.2.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155010" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080155019" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080155012" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080156" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0156: java-1.5.0-bea security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0156-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0156.html" />
          <reference source="CVE" ref_id="CVE-2007-5232" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5232.html" />
          <reference source="CVE" ref_id="CVE-2007-5239" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5239.html" />
          <reference source="CVE" ref_id="CVE-2007-5240" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5240.html" />
          <reference source="CVE" ref_id="CVE-2007-5273" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5273.html" />
          <reference source="CVE" ref_id="CVE-2008-0657" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0657.html" />
    
    <description>The BEA WebLogic JRockit 1.5.0_14 JRE and SDK contain BEA WebLogic JRockit
Virtual Machine 1.5.0_14 and are certified for the Java 5 Platform,
Standard Edition, v1.5.0.

A flaw in the applet caching mechanism of the Java Runtime Environment
(JRE) did not correctly process the creation of network connections. A
remote attacker could use this flaw to create connections to services on
machines other than the one that the applet was downloaded from.
(CVE-2007-5232)

Untrusted Java Applets were able to drag and drop a file to a Desktop
Application. A user-assisted remote attacker could use this flaw to move or
copy arbitrary files. (CVE-2007-5239)

The Java Runtime Environment (JRE) allowed untrusted Java Applets or
applications to display oversized windows. This could be used by remote
attackers to hide security warning banners. (CVE-2007-5240)

Unsigned Java Applets communicating via a HTTP proxy could allow a remote
attacker to violate the Java security model. A cached, malicious Applet
could create network connections to services on other machines. (CVE-2007-5273)

Two vulnerabilities in the Java Runtime Environment allowed an untrusted
application or applet to elevate the assigned privileges. This could be
misused by a malicious website to read and write local files or execute
local applications in the context of the user running the Java process.
(CVE-2008-0657)

Those vulnerabilities concerned with applets can only be triggered in
java-1.5.0-bea by calling the 'appletviewer' application. 

All users of java-1.5.0-bea should upgrade to these updated packages, which
contain the BEA WebLogic JRockit 1.5.0_14 release that resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-05" />
        <updated date="2008-03-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5232.html">CVE-2007-5232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5239.html">CVE-2007-5239</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5240.html">CVE-2007-5240</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5273.html">CVE-2007-5273</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0657.html">CVE-2008-0657</cve>
                <bugzilla href="http://bugzilla.redhat.com/321951" id="321951">CVE-2007-5232 Security Vulnerability in Java Runtime Environment With Applet Caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321981" id="321981">CVE-2007-5239 Untrusted Application or Applet May Move or Copy Arbitrary Files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/321991" id="321991">CVE-2007-5240 Applets or Applications are allowed to display an oversized window</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/324351" id="324351">CVE-2007-5273 Anti-DNS Pinning and Java Applets with HTTP proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431861" id="431861">CVE-2008-0657 java-1.5.0 Privilege escalation via unstrusted applet and application</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080156002" comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156003" comment="java-1.5.0-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080156012" comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156013" comment="java-1.5.0-bea-missioncontrol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080156004" comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156005" comment="java-1.5.0-bea-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080156008" comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156009" comment="java-1.5.0-bea-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080156010" comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156011" comment="java-1.5.0-bea-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080156006" comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156007" comment="java-1.5.0-bea-demo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080157" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0157: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0157-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0157.html" />
          <reference source="CVE" ref_id="CVE-2008-0882" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0882.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems. The Internet Printing Protocol (IPP) is a
standard network protocol for remote printing, as well as managing print
jobs.

A flaw was found in the way CUPS handles the addition and removal of remote
shared printers via IPP. A remote attacker could send malicious UDP IPP
packets causing the CUPS daemon to crash. (CVE-2008-0882)

Note: the default configuration of CUPS on Red Hat Enterprise Linux 5 will
only accept requests of this type from the local subnet. This issue did not
affect the versions of CUPS as shipped with Red Hat Enterprise Linux 3 or
4.

All cups users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-21" />
        <updated date="2008-02-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0882.html">CVE-2008-0882</cve>
                <bugzilla href="http://bugzilla.redhat.com/433758" id="433758">CVE-2008-0882 cups: double free vulnerability in process_browse_data()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080157006" comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080157004" comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080157008" comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080157002" comment="cups is earlier than 1:1.2.4-11.14.el5_1.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080159" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0159: dbus security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0159-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0159.html" />
          <reference source="CVE" ref_id="CVE-2008-0595" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0595.html" />
    
    <description>D-Bus is a system for sending messages between applications. It is used
both for the system-wide message bus service, and as a
per-user-login-session messaging facility.

Havoc Pennington discovered a flaw in the way the dbus-daemon applies its
security policy. A user with the ability to connect to the dbus-daemon may
be able to execute certain method calls they should normally not have
permission to access.  (CVE-2008-0595)

Red Hat does not ship any applications in Red Hat Enterprise Linux 5 that
would allow a user to leverage this flaw to elevate their privileges.

This flaw does not affect the version of D-Bus shipped in Red Hat
Enterprise Linux 4.

All users are advised to upgrade to these updated dbus packages, which
contain a backported patch and are not vulnerable to this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-27" />
        <updated date="2008-02-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0595.html">CVE-2008-0595</cve>
                <bugzilla href="http://bugzilla.redhat.com/432419" id="432419">CVE-2008-0595 dbus security policy circumvention</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080159004" comment="dbus-x11 is earlier than 0:1.0.0-6.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080159005" comment="dbus-x11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080159006" comment="dbus-devel is earlier than 0:1.0.0-6.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080159007" comment="dbus-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080159002" comment="dbus is earlier than 0:1.0.0-6.3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080159003" comment="dbus is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080161" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0161: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0161-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0161.html" />
          <reference source="CVE" ref_id="CVE-2008-0596" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0596.html" />
          <reference source="CVE" ref_id="CVE-2008-0597" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0597.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A flaw was found in the way CUPS handled the addition and removal of remote
shared printers via IPP.  A remote attacker could send malicious UDP IPP
packets causing the CUPS daemon to attempt to dereference already freed
memory and crash. (CVE-2008-0597)

A memory management flaw was found in the way CUPS handled the addition and
removal of remote shared printers via IPP.  When shared printer was
removed, allocated memory was not properly freed, leading to a memory leak
possibly causing CUPS daemon crash after exhausting available memory.
(CVE-2008-0596)

These issues were found during the investigation of CVE-2008-0882, which
did not affect Red Hat Enterprise Linux 4.

Note that the default configuration of CUPS on Red Hat Enterprise Linux
4 allow requests of this type only from the local subnet.

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-02-25" />
        <updated date="2008-02-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0596.html">CVE-2008-0596</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0597.html">CVE-2008-0597</cve>
                <bugzilla href="http://bugzilla.redhat.com/433825" id="433825">CVE-2008-0596 cups: memory leak handling IPP browse requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433847" id="433847">CVE-2008-0597 cups: dereference of free'd memory handling IPP browse requests</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080161004" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080161006" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080161002" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080164" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0164: krb5 security and bugfix update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0164.html" />
          <reference source="CVE" ref_id="CVE-2007-5901" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5901.html" />
          <reference source="CVE" ref_id="CVE-2007-5971" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5971.html" />
          <reference source="CVE" ref_id="CVE-2008-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0062.html" />
          <reference source="CVE" ref_id="CVE-2008-0063" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0063.html" />
          <reference source="CVE" ref_id="CVE-2008-0947" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0947.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the way the MIT Kerberos Authentication Service and Key
Distribution Center server (krb5kdc) handled Kerberos v4 protocol packets.
An unauthenticated remote attacker could use this flaw to crash the
krb5kdc daemon, disclose portions of its memory, or possibly execute
arbitrary code using malformed or truncated Kerberos v4 protocol requests.
(CVE-2008-0062, CVE-2008-0063)

This issue only affected krb5kdc with Kerberos v4 protocol compatibility
enabled, which is the default setting on Red Hat Enterprise Linux 4.
Kerberos v4 protocol support can be disabled by adding "v4_mode=none"
(without the quotes) to the "[kdcdefaults]" section of
/var/kerberos/krb5kdc/kdc.conf.

Jeff Altman of Secure Endpoints discovered a flaw in the RPC library as
used by MIT Kerberos kadmind server. An unauthenticated remote attacker
could use this flaw to crash kadmind or possibly execute arbitrary code.
This issue only affected systems with certain resource limits configured
and did not affect systems using default resource limits used by Red Hat
Enterprise Linux 5. (CVE-2008-0947)

Red Hat would like to thank MIT for reporting these issues.

Multiple memory management flaws were discovered in the GSSAPI library used
by MIT Kerberos. These flaws could possibly result in use of already freed
memory or an attempt to free already freed memory blocks (double-free
flaw), possibly causing a crash or arbitrary code execution.
(CVE-2007-5901, CVE-2007-5971)

In addition to the security issues resolved above, the following bugs were
also fixed:

* delegated krb5 credentials were not properly stored when SPNEGO was the
underlying mechanism during GSSAPI authentication. Consequently,
applications attempting to copy delegated Kerberos 5 credentials into a
credential cache received an "Invalid credential was supplied" message
rather than a copy of the delegated credentials. With this update, SPNEGO
credentials can be properly searched, allowing applications to copy
delegated credentials as expected.

* applications can initiate context acceptance (via gss_accept_sec_context)
without passing a ret_flags value that would indicate that credentials were
delegated. A delegated credential handle should have been returned in such
instances. This updated package adds a temp_ret_flag that stores the
credential status in the event no other ret_flags value is passed by an
application calling gss_accept_sec_context.

* kpasswd did not fallback to TCP on receipt of certain errors, or when a
packet was too big for UDP. This update corrects this.

* when the libkrb5 password-routine generated a set-password or
change-password request, incorrect sequence numbers were generated for all
requests subsequent to the first request. This caused password change
requests to fail if the primary server was unavailable. This updated
package corrects this by saving the sequence number value after the AP-REQ
data is built and restoring this value before the request is generated.

* when a user's password expired, kinit would not prompt that user to
change the password, instead simply informing the user their password had
expired. This update corrects this behavior: kinit now prompts for a new
password to be set when a password has expired.

All krb5 users are advised to upgrade to these updated packages, which
contain backported fixes to address these vulnerabilities and fix these
bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-18" />
        <updated date="2008-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5901.html">CVE-2007-5901</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5971.html">CVE-2007-5971</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0062.html">CVE-2008-0062</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0063.html">CVE-2008-0063</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0947.html">CVE-2008-0947</cve>
                <bugzilla href="http://bugzilla.redhat.com/415321" id="415321">CVE-2007-5901 krb5: use-after-free in gssapi lib</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/415351" id="415351">CVE-2007-5971 krb5: double free in gssapi lib</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432620" id="432620">CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432621" id="432621">CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433596" id="433596">CVE-2008-0947 krb5: file descriptor array overflow in RPC library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436460" id="436460">gss_krb5_copy_ccache can't find delegated Kerberos creds when using SPNEGO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436465" id="436465">gss_init_sec_context() mechglue wrapper doesn't handle ret_flags right</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436467" id="436467">kpasswd does not fallback to tcp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436468" id="436468">krb5 password changing uses incorrect sequence numbers for every server but the first</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436470" id="436470">kinit does not automatically start a password change when password is expired</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080164006" comment="krb5-libs is earlier than 0:1.6.1-17.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080164007" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080164004" comment="krb5-devel is earlier than 0:1.6.1-17.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080164005" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080164008" comment="krb5-server is earlier than 0:1.6.1-17.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080164009" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080164002" comment="krb5 is earlier than 0:1.6.1-17.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080164003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080164010" comment="krb5-workstation is earlier than 0:1.6.1-17.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080164011" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080167" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0167: kernel security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0167-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0167.html" />
          <reference source="CVE" ref_id="CVE-2007-5904" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5904.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

A buffer overflow flaw was found in the CIFS virtual file system. A
remote authenticated user could issue a request that could lead to
a denial of service. (CVE-2007-5904, Moderate)

As well, these updated packages fix the following bugs:

* a bug was found in the Linux kernel audit subsystem. When the audit
daemon was setup to log the execve system call with a large number
of arguments, the kernel could run out out memory while attempting to
create audit log messages. This could cause a kernel panic. In these
updated packages, large audit messages are split into acceptable sizes,
which resolves this issue.

* on certain Intel chipsets, it was not possible to load the acpiphp
module using the "modprobe acpiphp" command. Because the acpiphp module
did not recurse across PCI bridges, hardware detection for PCI hot plug
slots failed. In these updated packages, hardware detection works
correctly.

* on IBM System z architectures that run the IBM z/VM hypervisor, the IBM
eServer zSeries HiperSockets network interface (layer 3) allowed ARP
packets to be sent and received, even when the "NOARP" flag was set. These
ARP packets caused problems for virtual machines.

* it was possible for the iounmap function to sleep while holding a lock.
This may have caused a deadlock for drivers and other code that uses the
iounmap function. In these updated packages, the lock is dropped before
the sleep code is called, which resolves this issue.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-14" />
        <updated date="2008-03-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5904.html">CVE-2007-5904</cve>
                <bugzilla href="http://bugzilla.redhat.com/372701" id="372701">CVE-2007-5904 Buffer overflow in CIFS VFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427393" id="427393">audit: Logging execve arguments, out of memory in audit_expand</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428174" id="428174">ACPIPHP.ko will not load : RHEL4.x and RHEL5.0 on X8450 (Intel 4 socket Quad Core) but will load on RHEL5.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430670" id="430670">LTC39262-qeth: HiperSockets layer-3 interface to drop non-IP packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433267" id="433267">[Stratus 4.6.z bug] iounmap may sleep while holding vmlist_lock, causing a deadlock.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167002" comment="kernel is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167022" comment="kernel-doc is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167004" comment="kernel-devel is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167008" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167018" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167016" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167010" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167012" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167006" comment="kernel-xenU is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080167014" comment="kernel-smp is earlier than 0:2.6.9-67.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080175" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0175: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0175-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0175.html" />
          <reference source="CVE" ref_id="CVE-2007-5746" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5746.html" />
          <reference source="CVE" ref_id="CVE-2008-0320" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0320.html" />
          <reference source="CVE" ref_id="CVE-2007-5745" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5745.html" />
          <reference source="CVE" ref_id="CVE-2007-5747" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5747.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Multiple heap overflows and an integer underflow were found in the Quattro
Pro(R) import filter. An attacker could create a carefully crafted Quattro
Pro file that could cause OpenOffice.org to crash or possibly execute
arbitrary code if the file was opened by a victim. (CVE-2007-5745,
CVE-2007-5747)

A heap overflow flaw was found in the EMF parser. An attacker could create
a carefully crafted EMF file that could cause OpenOffice.org to crash or
possibly execute arbitrary code if the malicious EMF image was added to a
document or if a document containing the malicious EMF file was opened by a
victim. (CVE-2007-5746)

A heap overflow flaw was found in the OLE Structured Storage file parser.
(OLE Structured Storage is a format used by Microsoft Office documents.) An
attacker could create a carefully crafted OLE file that could cause
OpenOffice.org to crash or possibly execute arbitrary code if the file was
opened by a victim. (CVE-2008-0320)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-17" />
        <updated date="2008-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5746.html">CVE-2007-5746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0320.html">CVE-2008-0320</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5745.html">CVE-2007-5745</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5747.html">CVE-2007-5747</cve>
                <bugzilla href="http://bugzilla.redhat.com/435675" id="435675">CVE-2007-5746 openoffice.org: EMF files parsing EMR_BITBLT record heap overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435676" id="435676">CVE-2008-0320 openoffice.org: OLE files parsing heap overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435678" id="435678">CVE-2007-5745 openoffice.org: Quattro Pro files handling heap overflows in Attribute and Font records</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435681" id="435681">CVE-2007-5747 openoffice.org: Quattro Pro files parsing integer underflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175148" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175149" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175002" comment="openoffice.org is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175072" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175073" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175078" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175079" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175118" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175119" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175088" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175089" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175046" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175047" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175124" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175125" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175030" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175031" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175100" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175101" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175094" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175095" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175042" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175043" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175016" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175017" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175106" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175107" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175096" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175097" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175076" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175077" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175050" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175051" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175134" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175135" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175102" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175103" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175130" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175131" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175008" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175009" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175066" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175067" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175146" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175147" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175132" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175133" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175028" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175029" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175108" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175109" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175114" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175115" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175048" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175049" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175080" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175081" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175022" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175023" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175036" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175037" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175144" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175145" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175024" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175025" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175104" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175105" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175110" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175111" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175006" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175007" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175010" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175011" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175062" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175063" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175014" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175015" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175074" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175075" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175034" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175035" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175012" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175013" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175126" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175127" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175112" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175113" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175068" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175069" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175142" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175143" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175136" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175137" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175026" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175027" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175038" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175039" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175128" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175129" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175092" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175093" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175122" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175123" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175044" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175045" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175056" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175057" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175140" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175141" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175084" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175085" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175032" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175098" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175099" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175120" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175121" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175020" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175021" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175090" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175091" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175070" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175071" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175116" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175117" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175054" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175055" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175138" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175139" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175064" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175065" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175004" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175005" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175040" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175041" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175060" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175061" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175058" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175059" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175086" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175087" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175018" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175019" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175052" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175053" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175082" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.26" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175083" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175265" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175266" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175261" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175262" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175257" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175258" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175243" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175244" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175227" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175228" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175213" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175214" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175183" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175184" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175175" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175176" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175251" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175252" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175225" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175226" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175217" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175218" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175207" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175208" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175185" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175186" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175229" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175230" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175193" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175194" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175191" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175192" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175241" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175242" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175219" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175220" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175159" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175160" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175205" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175206" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175151" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175152" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175255" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175256" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175249" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175250" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175247" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175248" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175239" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175240" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175215" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175216" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175211" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175212" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175181" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175182" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175177" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175178" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175173" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175174" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175163" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175164" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175157" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175158" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175153" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175154" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175263" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175264" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175233" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175234" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175223" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175224" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175209" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175210" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175161" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175162" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175259" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175260" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175253" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175254" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175245" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175246" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175235" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175236" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175201" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175202" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175189" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175190" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175169" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175170" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175155" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175156" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175231" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175232" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175221" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175222" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175171" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175172" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175167" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175168" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175267" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175268" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175237" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175238" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175199" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175200" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175197" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175198" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175195" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175196" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175187" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175188" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175179" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175180" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175165" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175166" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080175203" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.4.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175204" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080176" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0176: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0176.html" />
          <reference source="CVE" ref_id="CVE-2007-5746" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5746.html" />
          <reference source="CVE" ref_id="CVE-2008-0320" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0320.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

A heap overflow flaw was found in the EMF parser. An attacker could create
a carefully crafted EMF file that could cause OpenOffice.org to crash or
possibly execute arbitrary code if the malicious EMF image was added to a
document or if a document containing the malicious EMF file was opened by a
victim. (CVE-2007-5746)

A heap overflow flaw was found in the OLE Structured Storage file parser.
(OLE Structured Storage is a format used by Microsoft Office documents.) An
attacker could create a carefully crafted OLE file that could cause
OpenOffice.org to crash or possibly execute arbitrary code if the file was
opened by a victim. (CVE-2008-0320)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-17" />
        <updated date="2008-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5746.html">CVE-2007-5746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0320.html">CVE-2008-0320</cve>
                <bugzilla href="http://bugzilla.redhat.com/435675" id="435675">CVE-2007-5746 openoffice.org: EMF files parsing EMR_BITBLT record heap overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435676" id="435676">CVE-2008-0320 openoffice.org: OLE files parsing heap overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176006" comment="openoffice.org-i18n is earlier than 0:1.1.2-41.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176002" comment="openoffice.org is earlier than 0:1.1.2-41.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176004" comment="openoffice.org-libs is earlier than 0:1.1.2-41.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176011" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176009" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176012" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080176010" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.3.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080177" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0177: evolution security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0177-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0177.html" />
          <reference source="CVE" ref_id="CVE-2008-0072" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0072.html" />
    
    <description>Evolution is the GNOME collection of personal information management (PIM)
tools.

A format string flaw was found in the way Evolution displayed encrypted
mail content. If a user opened a carefully crafted mail message, arbitrary
code could be executed as the user running Evolution. (CVE-2008-0072)

All users of Evolution should upgrade to these updated packages, which
contain a backported patch which resolves this issue.

Red Hat would like to thank Ulf Härnhammar of Secunia Research for finding
and reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-05" />
        <updated date="2008-03-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0072.html">CVE-2008-0072</cve>
                <bugzilla href="http://bugzilla.redhat.com/435759" id="435759">CVE-2008-0072 Evolution format string flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080177002" comment="evolution is earlier than 0:2.8.0-40.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177003" comment="evolution is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080177004" comment="evolution-devel is earlier than 0:2.8.0-40.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177005" comment="evolution-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080177007" comment="evolution is earlier than 0:2.0.2-35.0.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177008" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080177009" comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177010" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080177011" comment="evolution28 is earlier than 0:2.8.0-53.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177012" comment="evolution28 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080177013" comment="evolution28-devel is earlier than 0:2.8.0-53.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177014" comment="evolution28-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080180" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0180: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0180.html" />
          <reference source="CVE" ref_id="CVE-2007-5971" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5971.html" />
          <reference source="CVE" ref_id="CVE-2008-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0062.html" />
          <reference source="CVE" ref_id="CVE-2008-0063" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0063.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the way the MIT Kerberos Authentication Service and Key
Distribution Center server (krb5kdc) handled Kerberos v4 protocol packets.
An unauthenticated remote attacker could use this flaw to crash the
krb5kdc daemon, disclose portions of its memory, or possibly execute
arbitrary code using malformed or truncated Kerberos v4 protocol
requests. (CVE-2008-0062, CVE-2008-0063)

This issue only affected krb5kdc with Kerberos v4 protocol compatibility
enabled, which is the default setting on Red Hat Enterprise Linux 4.
Kerberos v4 protocol support can be disabled by adding "v4_mode=none"
(without the quotes) to the "[kdcdefaults]" section of
/var/kerberos/krb5kdc/kdc.conf.

Red Hat would like to thank MIT for reporting these issues.

A double-free flaw was discovered in the GSSAPI library used by MIT
Kerberos. This flaw could possibly cause a crash of the application using
the GSSAPI library. (CVE-2007-5971)

All krb5 users are advised to update to these erratum packages which
contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-18" />
        <updated date="2008-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5971.html">CVE-2007-5971</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0062.html">CVE-2008-0062</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0063.html">CVE-2008-0063</cve>
                <bugzilla href="http://bugzilla.redhat.com/415351" id="415351">CVE-2007-5971 krb5: double free in gssapi lib</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432620" id="432620">CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432621" id="432621">CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080180004" comment="krb5-libs is earlier than 0:1.3.4-54.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180005" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080180006" comment="krb5-devel is earlier than 0:1.3.4-54.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180007" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080180008" comment="krb5-server is earlier than 0:1.3.4-54.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080180002" comment="krb5 is earlier than 0:1.3.4-54.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080180010" comment="krb5-workstation is earlier than 0:1.3.4-54.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080181" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0181: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0181-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0181.html" />
          <reference source="CVE" ref_id="CVE-2008-0062" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0062.html" />
          <reference source="CVE" ref_id="CVE-2008-0063" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0063.html" />
          <reference source="CVE" ref_id="CVE-2008-0948" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0948.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other through use of symmetric encryption
and a trusted third party, the KDC.

A flaw was found in the way the MIT Kerberos Authentication Service and Key
Distribution Center server (krb5kdc) handled Kerberos v4 protocol packets.
An unauthenticated remote attacker could use this flaw to crash the
krb5kdc daemon, disclose portions of its memory, or possibly execute
arbitrary code using malformed or truncated Kerberos v4 protocol
requests. (CVE-2008-0062, CVE-2008-0063)

This issue only affected krb5kdc with Kerberos v4 protocol compatibility
enabled, which is the default setting on Red Hat Enterprise Linux 4.
Kerberos v4 protocol support can be disabled by adding "v4_mode=none"
(without the quotes) to the "[kdcdefaults]" section of
/var/kerberos/krb5kdc/kdc.conf.

A flaw was found in the RPC library used by the MIT Kerberos kadmind
server. An unauthenticated remote attacker could use this flaw to crash
kadmind. This issue only affected systems with certain resource limits
configured and did not affect systems using default resource limits used by
Red Hat Enterprise Linux 2.1 or 3. (CVE-2008-0948)

Red Hat would like to thank MIT for reporting these issues.

All krb5 users are advised to update to these erratum packages which
contain backported fixes to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-18" />
        <updated date="2008-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0062.html">CVE-2008-0062</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0063.html">CVE-2008-0063</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0948.html">CVE-2008-0948</cve>
                <bugzilla href="http://bugzilla.redhat.com/432620" id="432620">CVE-2008-0062 krb5: uninitialized pointer use in krb5kdc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432621" id="432621">CVE-2008-0063 krb5: possible leak of sensitive data from krb5kdc using krb4 request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435087" id="435087">CVE-2008-0948 krb5: incorrect handling of high-numbered file descriptors in RPC library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080181008" comment="krb5-libs is earlier than 0:1.2.7-68" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180005" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080181010" comment="krb5-devel is earlier than 0:1.2.7-68" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180007" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080181006" comment="krb5-server is earlier than 0:1.2.7-68" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180009" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080181002" comment="krb5 is earlier than 0:1.2.7-68" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080181004" comment="krb5-workstation is earlier than 0:1.2.7-68" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080180011" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080186" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0186: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0186-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0186.html" />
          <reference source="CVE" ref_id="CVE-2008-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1185.html" />
          <reference source="CVE" ref_id="CVE-2008-1186" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1186.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
          <reference source="CVE" ref_id="CVE-2008-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1188.html" />
          <reference source="CVE" ref_id="CVE-2008-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1189.html" />
          <reference source="CVE" ref_id="CVE-2008-1190" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1190.html" />
          <reference source="CVE" ref_id="CVE-2008-1192" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1192.html" />
          <reference source="CVE" ref_id="CVE-2008-1193" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1193.html" />
          <reference source="CVE" ref_id="CVE-2008-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1194.html" />
          <reference source="CVE" ref_id="CVE-2008-1195" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1195.html" />
          <reference source="CVE" ref_id="CVE-2008-1196" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1196.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools
that users need to run applets and applications written using the Java
programming language. 

Flaws in the JRE allowed an untrusted application or applet to elevate its
privileges. This could be exploited by a remote attacker to access local
files or execute local applications accessible to the user running the JRE
(CVE-2008-1185, CVE-2008-1186)

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187)

Several buffer overflow flaws were found in Java Web Start (JWS). An
untrusted JNLP application could access local files or execute local
applications accessible to the user running the JRE.
(CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1196)

A flaw was found in the Java Plug-in. A remote attacker could bypass the
same origin policy, executing arbitrary code with the permissions of the
user running the JRE. (CVE-2008-1192)

A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possible execute
arbitrary code with the permissions of the user running the JRE.
(CVE-2008-1193)

A flaw was found in the JRE color management library.  An untrusted
application or applet could trigger a denial of service (JVM crash).
(CVE-2008-1194)

The JRE allowed untrusted JavaScript code to create local network
connections by the use of Java APIs.  A remote attacker could use these
flaws to acesss local network services. (CVE-2008-1195)

This update also fixes an issue where the Java Plug-in is not available for
browser use after successful installation.

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-06" />
        <updated date="2008-03-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1185.html">CVE-2008-1185</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1186.html">CVE-2008-1186</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1188.html">CVE-2008-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1189.html">CVE-2008-1189</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1190.html">CVE-2008-1190</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1192.html">CVE-2008-1192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1193.html">CVE-2008-1193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1194.html">CVE-2008-1194</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1195.html">CVE-2008-1195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1196.html">CVE-2008-1196</cve>
                <bugzilla href="http://bugzilla.redhat.com/436029" id="436029">CVE-2008-1185 Untrusted applet and application privilege escalation (CVE-2008-1186)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436293" id="436293">CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436295" id="436295">CVE-2008-1192 Java Plugin same-origin-policy bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436296" id="436296">CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436299" id="436299">CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436302" id="436302">CVE-2008-1196 Buffer overflow security vulnerabilities in Java Web Start</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080186012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080186002" comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080186008" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123011" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080186010" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080186006" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123009" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080186004" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123005" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080192" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0192: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0192-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0192.html" />
          <reference source="CVE" ref_id="CVE-2008-0047" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0047.html" />
          <reference source="CVE" ref_id="CVE-2008-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0053.html" />
          <reference source="CVE" ref_id="CVE-2008-1373" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1373.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A heap buffer overflow flaw was found in a CUPS administration interface
CGI script. A local attacker able to connect to the IPP port (TCP port 631)
could send a malicious request causing the script to crash or, potentially,
execute arbitrary code as the "lp" user. Please note: the default CUPS
configuration in Red Hat Enterprise Linux 5 does not allow remote
connections to the IPP TCP port. (CVE-2008-0047)

Red Hat would like to thank "regenrecht" for reporting this issue.

This issue did not affect the versions of CUPS as shipped with Red Hat
Enterprise Linux 3 or 4.

Two overflows were discovered in the HP-GL/2-to-PostScript filter. An
attacker could create a malicious HP-GL/2 file that could possibly execute
arbitrary code as the "lp" user if the file is printed. (CVE-2008-0053)

A buffer overflow flaw was discovered in the GIF decoding routines used by
CUPS image converting filters "imagetops" and "imagetoraster". An attacker
could create a malicious GIF file that could possibly execute arbitrary
code as the "lp" user if the file was printed. (CVE-2008-1373)

All cups users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-01" />
        <updated date="2008-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0047.html">CVE-2008-0047</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0053.html">CVE-2008-0053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1373.html">CVE-2008-1373</cve>
                <bugzilla href="http://bugzilla.redhat.com/436153" id="436153">CVE-2008-0047 cups: heap based buffer overflow in cgiCompileSearch()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438117" id="438117">CVE-2008-0053 cups: buffer overflows in HP-GL/2 filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438303" id="438303">CVE-2008-1373 cups: overflow in gif image filter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080192008" comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080192006" comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080192004" comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080192002" comment="cups is earlier than 1:1.2.4-11.14.el5_1.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080194" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0194: xen security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0194-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0194.html" />
          <reference source="CVE" ref_id="CVE-2007-3919" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3919.html" />
          <reference source="CVE" ref_id="CVE-2007-5730" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5730.html" />
          <reference source="CVE" ref_id="CVE-2008-0928" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0928.html" />
          <reference source="CVE" ref_id="CVE-2008-1943" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1943.html" />
          <reference source="CVE" ref_id="CVE-2008-1944" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1944.html" />
          <reference source="CVE" ref_id="CVE-2008-2004" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2004.html" />
    
    <description>The xen packages contain tools for managing the virtual machine monitor in
Red Hat Virtualization.

These updated packages fix the following security issues:

Daniel P. Berrange discovered that the hypervisor's para-virtualized
framebuffer (PVFB) backend failed to validate the format of messages
serving to update the contents of the framebuffer. This could allow a
malicious user to cause a denial of service, or compromise the privileged
domain (Dom0). (CVE-2008-1944)

Markus Armbruster discovered that the hypervisor's para-virtualized
framebuffer (PVFB) backend failed to validate the frontend's framebuffer
description. This could allow a malicious user to cause a denial of
service, or to use a specially crafted frontend to compromise the
privileged domain (Dom0). (CVE-2008-1943)

Chris Wright discovered a security vulnerability in the QEMU block format
auto-detection, when running fully-virtualized guests. Such
fully-virtualized guests, with a raw formatted disk image, were able
to write a header to that disk image describing another format. This could
allow such guests to read arbitrary files in their hypervisor's host.
(CVE-2008-2004)

Ian Jackson discovered a security vulnerability in the QEMU block device
drivers backend. A guest operating system could issue a block device
request and read or write arbitrary memory locations, which could lead to
privilege escalation. (CVE-2008-0928)

Tavis Ormandy found that QEMU did not perform adequate sanity-checking of
data received via the "net socket listen" option. A malicious local
administrator of a guest domain could trigger this flaw to potentially
execute arbitrary code outside of the domain. (CVE-2007-5730)

Steve Kemp discovered that the xenbaked daemon and the XenMon utility
communicated via an insecure temporary file. A malicious local
administrator of a guest domain could perform a symbolic link attack,
causing arbitrary files to be truncated. (CVE-2007-3919)

As well, in the previous xen packages, it was possible for Dom0 to fail to
flush data from a fully-virtualized guest to disk, even if the guest
explicitly requested the flush. This could cause data integrity problems on
the guest. In these updated packages, Dom0 always respects the request to
flush to disk.

Users of xen are advised to upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-13" />
        <updated date="2008-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3919.html">CVE-2007-3919</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5730.html">CVE-2007-5730</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0928.html">CVE-2008-0928</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1943.html">CVE-2008-1943</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1944.html">CVE-2008-1944</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2004.html">CVE-2008-2004</cve>
                <bugzilla href="http://bugzilla.redhat.com/350421" id="350421">CVE-2007-3919 xen xenmon.py / xenbaked insecure temporary file accesss</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/360381" id="360381">CVE-2007-5730 QEMU Buffer overflow via crafted "net socket listen" option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433560" id="433560">CVE-2008-0928 Qemu insufficient block device address range checking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435495" id="435495">[RHEL5.2]: LTC41676-Xen full virt has data integrity issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443078" id="443078">CVE-2008-1943 PVFB backend fails to validate frontend's framebuffer description</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443390" id="443390">CVE-2008-1944 PVFB SDL backend chokes on bogus screen updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444583" id="444583">CVE-2008-2004 qemu/kvm/xen: qemu block format auto-detection vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080194002" comment="xen is earlier than 0:3.0.3-41.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080194003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080194006" comment="xen-libs is earlier than 0:3.0.3-41.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080194007" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080194004" comment="xen-devel is earlier than 0:3.0.3-41.el5_1.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080194005" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080196" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0196: unzip security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0196-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0196.html" />
          <reference source="CVE" ref_id="CVE-2008-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0888.html" />
    
    <description>The unzip utility is used to list, test, or extract files from a zip
archive.

An invalid pointer flaw was found in unzip. If a user ran unzip on a
specially crafted file, an attacker could execute arbitrary code with that
user's privileges. (CVE-2008-0888)

Red Hat would like to thank Tavis Ormandy of the Google Security Team for
reporting this issue.

All unzip users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-18" />
        <updated date="2008-03-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0888.html">CVE-2008-0888</cve>
                <bugzilla href="http://bugzilla.redhat.com/431438" id="431438">CVE-2008-0888 unzip: free() called for uninitialized or already freed pointer</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080196002" comment="unzip is earlier than 0:5.50-36.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080196003" comment="unzip is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080197" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0197: gnome-screensaver security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0197-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0197.html" />
          <reference source="CVE" ref_id="CVE-2008-0887" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0887.html" />
    
    <description>gnome-screensaver is the GNOME project's official screen saver program.

A flaw was found in the way gnome-screensaver verified user passwords. When
a system used a remote directory service for login credentials, a local
attacker able to cause a network outage could cause gnome-screensaver to
crash, unlocking the screen. (CVE-2008-0887)

Users of gnome-screensaver should upgrade to this updated package, which
contains a backported patch to correct this issue.

</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-02" />
        <updated date="2008-04-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0887.html">CVE-2008-0887</cve>
                <bugzilla href="http://bugzilla.redhat.com/435773" id="435773">CVE-2008-0887 gnome-screensaver using NIS auth will unlock if NIS goes away</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080197002" comment="gnome-screensaver is earlier than 0:2.16.1-5.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080197003" comment="gnome-screensaver is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080206" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0206: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0206.html" />
          <reference source="CVE" ref_id="CVE-2008-0053" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0053.html" />
          <reference source="CVE" ref_id="CVE-2008-1373" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1373.html" />
          <reference source="CVE" ref_id="CVE-2008-1374" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1374.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

Two overflows were discovered in the HP-GL/2-to-PostScript filter. An
attacker could create a malicious HP-GL/2 file that could possibly execute
arbitrary code as the "lp" user if the file is printed. (CVE-2008-0053)

A buffer overflow flaw was discovered in the GIF decoding routines used by
CUPS image converting filters "imagetops" and "imagetoraster". An attacker
could create a malicious GIF file that could possibly execute arbitrary
code as the "lp" user if the file was printed. (CVE-2008-1373)

It was discovered that the patch used to address CVE-2004-0888 in CUPS
packages in Red Hat Enterprise Linux 3 and 4 did not completely resolve the
integer overflow in the "pdftops" filter on 64-bit platforms.  An attacker
could create a malicious PDF file that could possibly execute arbitrary
code as the "lp" user if the file was printed. (CVE-2008-1374)

All cups users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-01" />
        <updated date="2008-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0053.html">CVE-2008-0053</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1373.html">CVE-2008-1373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1374.html">CVE-2008-1374</cve>
                <bugzilla href="http://bugzilla.redhat.com/438117" id="438117">CVE-2008-0053 cups: buffer overflows in HP-GL/2 filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438303" id="438303">CVE-2008-1373 cups: overflow in gif image filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438336" id="438336">CVE-2008-1374 cups: incomplete fix for CVE-2004-0888 / CVE-2005-0206</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080206004" comment="cups-devel is earlier than 1:1.1.17-13.3.52" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080206006" comment="cups-libs is earlier than 1:1.1.17-13.3.52" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080206002" comment="cups is earlier than 1:1.1.17-13.3.52" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080206011" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080206010" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080206009" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080207" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0207: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0207-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0207.html" />
          <reference source="CVE" ref_id="CVE-2008-1233" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1233.html" />
          <reference source="CVE" ref_id="CVE-2008-1234" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1234.html" />
          <reference source="CVE" ref_id="CVE-2008-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1235.html" />
          <reference source="CVE" ref_id="CVE-2008-1236" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1236.html" />
          <reference source="CVE" ref_id="CVE-2008-1237" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1237.html" />
          <reference source="CVE" ref_id="CVE-2008-1238" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1238.html" />
          <reference source="CVE" ref_id="CVE-2008-1241" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1241.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of some malformed web content. A
web page containing such malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-1233, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237)

Several flaws were found in the display of malformed web content. A web
page containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2008-1234,
CVE-2008-1238, CVE-2008-1241)

All Firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-26" />
        <updated date="2008-03-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1233.html">CVE-2008-1233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1234.html">CVE-2008-1234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1235.html">CVE-2008-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1236.html">CVE-2008-1236</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1237.html">CVE-2008-1237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1238.html">CVE-2008-1238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1241.html">CVE-2008-1241</cve>
                <bugzilla href="http://bugzilla.redhat.com/438713" id="438713">CVE-2008-1233 Mozilla products XPCNativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438715" id="438715">CVE-2008-1234 universal XSS using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438717" id="438717">CVE-2008-1235 chrome privilege via wrong principal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438718" id="438718">CVE-2008-1236 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438721" id="438721">CVE-2008-1237 javascript crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438724" id="438724">CVE-2008-1238 Referrer spoofing bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438730" id="438730">CVE-2008-1241 XUL popup spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080207004" comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103005" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080207002" comment="firefox is earlier than 0:1.5.0.12-14.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080207007" comment="firefox is earlier than 0:1.5.0.12-0.14.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080208" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0208: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0208-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0208.html" />
          <reference source="CVE" ref_id="CVE-2008-0414" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0414.html" />
          <reference source="CVE" ref_id="CVE-2008-1233" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1233.html" />
          <reference source="CVE" ref_id="CVE-2008-1234" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1234.html" />
          <reference source="CVE" ref_id="CVE-2008-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1235.html" />
          <reference source="CVE" ref_id="CVE-2008-1236" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1236.html" />
          <reference source="CVE" ref_id="CVE-2008-1237" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1237.html" />
          <reference source="CVE" ref_id="CVE-2008-1238" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1238.html" />
          <reference source="CVE" ref_id="CVE-2008-1241" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1241.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the processing of some malformed web content. A
web page containing such malicious content could cause SeaMonkey to crash
or, potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-1233, CVE-2008-1235, CVE-2008-1236, CVE-2008-1237)

Several flaws were found in the display of malformed web content. A web
page containing specially-crafted content could, potentially, trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-1234,
CVE-2008-1238, CVE-2008-1241)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-03-27" />
        <updated date="2008-03-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0414.html">CVE-2008-0414</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1233.html">CVE-2008-1233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1234.html">CVE-2008-1234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1235.html">CVE-2008-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1236.html">CVE-2008-1236</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1237.html">CVE-2008-1237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1238.html">CVE-2008-1238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1241.html">CVE-2008-1241</cve>
                <bugzilla href="http://bugzilla.redhat.com/438713" id="438713">CVE-2008-1233 Mozilla products XPCNativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438715" id="438715">CVE-2008-1234 universal XSS using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438717" id="438717">CVE-2008-1235 chrome privilege via wrong principal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438718" id="438718">CVE-2008-1236 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438721" id="438721">CVE-2008-1237 javascript crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438724" id="438724">CVE-2008-1238 Referrer spoofing bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438730" id="438730">CVE-2008-1241 XUL popup spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208006" comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208004" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208020" comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208002" comment="seamonkey is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208012" comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208016" comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208014" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208010" comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208018" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208029" comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208032" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208028" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208031" comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208023" comment="seamonkey is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208025" comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208030" comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208026" comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208024" comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080208027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080209" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0209: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0209-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0209.html" />
          <reference source="CVE" ref_id="CVE-2008-1233" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1233.html" />
          <reference source="CVE" ref_id="CVE-2008-1234" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1234.html" />
          <reference source="CVE" ref_id="CVE-2008-1235" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1235.html" />
          <reference source="CVE" ref_id="CVE-2008-1236" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1236.html" />
          <reference source="CVE" ref_id="CVE-2008-1237" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1237.html" />
          <reference source="CVE" ref_id="CVE-2008-1238" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1238.html" />
          <reference source="CVE" ref_id="CVE-2008-1241" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1241.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of some malformed HTML mail
content. An HTML mail message containing such malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code as the user
running Thunderbird. (CVE-2008-1233, CVE-2008-1235, CVE-2008-1236,
CVE-2008-1237)

Several flaws were found in the display of malformed web content. An HTML
mail message containing specially-crafted content could, potentially, trick
a user into surrendering sensitive information. (CVE-2008-1234,
CVE-2008-1238, CVE-2008-1241)

Note: JavaScript support is disabled by default in Thunderbird; the above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-03" />
        <updated date="2008-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1233.html">CVE-2008-1233</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1234.html">CVE-2008-1234</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1235.html">CVE-2008-1235</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1236.html">CVE-2008-1236</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1237.html">CVE-2008-1237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1238.html">CVE-2008-1238</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1241.html">CVE-2008-1241</cve>
                <bugzilla href="http://bugzilla.redhat.com/438713" id="438713">CVE-2008-1233 Mozilla products XPCNativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438715" id="438715">CVE-2008-1234 universal XSS using event handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438717" id="438717">CVE-2008-1235 chrome privilege via wrong principal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438718" id="438718">CVE-2008-1236 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438721" id="438721">CVE-2008-1237 javascript crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438724" id="438724">CVE-2008-1238 Referrer spoofing bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438730" id="438730">CVE-2008-1241 XUL popup spoofing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080209002" comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080209005" comment="thunderbird is earlier than 0:1.5.0.12-10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080210" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0210: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0210-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0210.html" />
          <reference source="CVE" ref_id="CVE-2008-0657" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0657.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
          <reference source="CVE" ref_id="CVE-2008-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1188.html" />
          <reference source="CVE" ref_id="CVE-2008-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1189.html" />
          <reference source="CVE" ref_id="CVE-2008-1190" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1190.html" />
          <reference source="CVE" ref_id="CVE-2008-1192" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1192.html" />
          <reference source="CVE" ref_id="CVE-2008-1193" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1193.html" />
          <reference source="CVE" ref_id="CVE-2008-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1194.html" />
          <reference source="CVE" ref_id="CVE-2008-1195" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1195.html" />
          <reference source="CVE" ref_id="CVE-2008-1196" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1196.html" />
    
    <description>IBM's 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

Two vulnerabilities in the Java Runtime Environment allowed an untrusted
application or applet to elevate the assigned privileges. This could be
misused by a malicious website to read and write local files or execute
local applications in the context of the user running the Java process.
(CVE-2008-0657) 

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187) 

Several buffer overflow flaws were found in Java Web Start (JWS). An
untrusted JNLP application could access local files or execute local
applications accessible to the user running the JRE.
(CVE-2008-1188, CVE-2008-1189, CVE-2008-1190, CVE-2008-1196) 

A flaw was found in the Java Plug-in. A remote attacker could bypass the
same origin policy, executing arbitrary code with the permissions of the
user running the JRE. (CVE-2008-1192) 

A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possible execute
arbitrary code with the permissions of the user running the JRE.
(CVE-2008-1193)

A flaw was found in the JRE color management library. An untrusted
application or applet could trigger a denial of service (JVM crash).
(CVE-2008-1194)

The JRE allowed untrusted JavaScript code to create local network
connections by the use of Java APIs. A remote attacker could use these
flaws to acesss local network services. (CVE-2008-1195) 

All users of java-ibm-1.5.0 are advised to upgrade to these updated
packages, that contain IBM's 1.5.0 SR7 Java release which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-03" />
        <updated date="2008-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0657.html">CVE-2008-0657</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1188.html">CVE-2008-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1189.html">CVE-2008-1189</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1190.html">CVE-2008-1190</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1192.html">CVE-2008-1192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1193.html">CVE-2008-1193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1194.html">CVE-2008-1194</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1195.html">CVE-2008-1195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1196.html">CVE-2008-1196</cve>
                <bugzilla href="http://bugzilla.redhat.com/431861" id="431861">CVE-2008-0657 java-1.5.0 Privilege escalation via unstrusted applet and application</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436293" id="436293">CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436295" id="436295">CVE-2008-1192 Java Plugin same-origin-policy bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436296" id="436296">CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436299" id="436299">CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436302" id="436302">CVE-2008-1196 Buffer overflow security vulnerabilities in Java Web Start</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210006" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210010" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210011" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210014" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210012" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210004" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210016" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210017" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080210008" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210009" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080211" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0211: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0211-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0211.html" />
          <reference source="CVE" ref_id="CVE-2006-4814" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4814.html" />
          <reference source="CVE" ref_id="CVE-2007-5001" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5001.html" />
          <reference source="CVE" ref_id="CVE-2007-6151" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6151.html" />
          <reference source="CVE" ref_id="CVE-2007-6206" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6206.html" />
          <reference source="CVE" ref_id="CVE-2008-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0007.html" />
          <reference source="CVE" ref_id="CVE-2008-1367" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1367.html" />
          <reference source="CVE" ref_id="CVE-2008-1375" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1375.html" />
          <reference source="CVE" ref_id="CVE-2008-1669" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1669.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* the absence of a protection mechanism when attempting to access a
critical section of code has been found in the Linux kernel open file
descriptors control mechanism, fcntl. This could allow a local unprivileged
user to simultaneously execute code, which would otherwise be protected
against parallel execution. As well, a race condition when handling locks
in the Linux kernel fcntl functionality, may have allowed a process
belonging to a local unprivileged user to gain re-ordered access to the
descriptor table. (CVE-2008-1669, Important)

* the absence of a protection mechanism when attempting to access a
critical section of code, as well as a race condition, have been found in
the Linux kernel file system event notifier, dnotify. This could allow a
local unprivileged user to get inconsistent data, or to send arbitrary
signals to arbitrary system processes. (CVE-2008-1375, Important)

Red Hat would like to thank Nick Piggin for responsibly disclosing the
following issue:

* when accessing kernel memory locations, certain Linux kernel drivers
registering a fault handler did not perform required range checks. A local
unprivileged user could use this flaw to gain read or write access to
arbitrary kernel memory, or possibly cause a kernel crash.
(CVE-2008-0007, Important)

* a flaw was found when performing asynchronous input or output operations
on a FIFO special file. A local unprivileged user could use this flaw to
cause a kernel panic. (CVE-2007-5001, Important)

* a flaw was found in the way core dump files were created. If a local user
could get a root-owned process to dump a core file into a directory, which
the user has write access to, they could gain read access to that core
file. This could potentially grant unauthorized access to sensitive
information. (CVE-2007-6206, Moderate)

* a buffer overflow was found in the Linux kernel ISDN subsystem. A local
unprivileged user could use this flaw to cause a denial of service.
(CVE-2007-6151, Moderate)

* a race condition found in the mincore system core could allow a local
user to cause a denial of service (system hang). (CVE-2006-4814, Moderate)

* it was discovered that the Linux kernel handled string operations in the
opposite way to the GNU Compiler Collection (GCC). This could allow a local
unprivileged user to cause memory corruption. (CVE-2008-1367, Low)

As well, these updated packages fix the following bugs:

* a bug, which caused long delays when unmounting mounts containing a large
number of unused dentries, has been resolved.

* in the previous kernel packages, the kernel was unable to handle certain
floating point instructions on Itanium(R) architectures.

* on certain Intel CPUs, the Translation Lookaside Buffer (TLB) was not
flushed correctly, which caused machine check errors.

Red Hat Enterprise Linux 3 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-07" />
        <updated date="2008-05-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4814.html">CVE-2006-4814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5001.html">CVE-2007-5001</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6151.html">CVE-2007-6151</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6206.html">CVE-2007-6206</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0007.html">CVE-2008-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1367.html">CVE-2008-1367</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1375.html">CVE-2008-1375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1669.html">CVE-2008-1669</cve>
                <bugzilla href="http://bugzilla.redhat.com/306971" id="306971">CVE-2006-4814 kernel Race condition in mincore can cause "ps -ef" to hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/326251" id="326251">CVE-2007-5001 kernel asynchronous IO on a FIFO kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396861" id="396861">CVE-2007-6206 Issue with core dump owner</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/413731" id="413731">RHEL3: System hangs at unmount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425111" id="425111">CVE-2007-6151 I4L: fix isdn_ioctl memory issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428961" id="428961">CVE-2008-0007 kernel: insufficient range checks in fault handlers with mremap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437312" id="437312">CVE-2008-1367 Kernel doesn't clear DF for signal handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439754" id="439754">CVE-2008-1375 kernel: race condition in dnotify (local DoS, local roothole possible)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443433" id="443433">CVE-2008-1669 kernel: add rcu_read_lock() to fcheck() in both dnotify, locks.c and fix fcntl store/load race in locks.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211012" comment="kernel-source is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211013" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211002" comment="kernel is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211010" comment="kernel-doc is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211016" comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211014" comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211008" comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211009" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211006" comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211007" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080211004" comment="kernel-smp is earlier than 0:2.4.21-57.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080214" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0214: squid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0214-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0214.html" />
          <reference source="CVE" ref_id="CVE-2008-1612" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1612.html" />
    
    <description>Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A flaw was found in the way squid manipulated HTTP headers for cached
objects stored in system memory. An attacker could use this flaw to cause a
squid child process to exit. This interrupted existing connections and made
proxy services unavailable. Note: the parent squid process started a new
child process, so this attack only resulted in a temporary denial of
service. (CVE-2008-1612)

Users of squid are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-08" />
        <updated date="2008-04-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1612.html">CVE-2008-1612</cve>
                <bugzilla href="http://bugzilla.redhat.com/439801" id="439801">CVE-2008-1612 squid: regression in SQUID-2007:2 / CVE-2007-6239</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080214002" comment="squid is earlier than 7:2.6.STABLE6-5.el5_1.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080214003" comment="squid is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080214005" comment="squid is earlier than 7:2.5.STABLE3-9.3E" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080214006" comment="squid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080214008" comment="squid is earlier than 7:2.5.STABLE14-1.4E.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080214006" comment="squid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080218" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0218: gnome-screensaver security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0218-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0218.html" />
          <reference source="CVE" ref_id="CVE-2008-0887" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0887.html" />
    
    <description>gnome-screensaver is the GNOME project's official screen saver program.

A flaw was found in the way gnome-screensaver verified user passwords. When
a system used a remote directory service for login credentials, a local
attacker able to cause a network outage could cause gnome-screensaver to
crash, unlocking the screen. (CVE-2008-0887)

Users of gnome-screensaver should upgrade to this updated package, which
contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-03" />
        <updated date="2008-04-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0887.html">CVE-2008-0887</cve>
                <bugzilla href="http://bugzilla.redhat.com/435773" id="435773">CVE-2008-0887 gnome-screensaver using NIS auth will unlock if NIS goes away</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080218002" comment="gnome-screensaver is earlier than 0:2.16.1-8.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080197003" comment="gnome-screensaver is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080221" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0221: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0221-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0221.html" />
          <reference source="CVE" ref_id="CVE-2007-5275" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5275.html" />
          <reference source="CVE" ref_id="CVE-2007-6243" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6243.html" />
          <reference source="CVE" ref_id="CVE-2007-6637" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6637.html" />
          <reference source="CVE" ref_id="CVE-2007-6019" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6019.html" />
          <reference source="CVE" ref_id="CVE-2007-0071" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-0071.html" />
          <reference source="CVE" ref_id="CVE-2008-1655" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1655.html" />
          <reference source="CVE" ref_id="CVE-2008-1654" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1654.html" />
          <reference source="CVE" ref_id="CVE-2008-3872" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3872.html" />
    
    <description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
Web browser plug-in.

Several input validation flaws were found in the way Flash Player displayed
certain content. These may have made it possible to execute arbitrary code
on a victim's machine, if the victim opened a malicious Adobe Flash file.
(CVE-2007-0071, CVE-2007-6019)

A flaw was found in the way Flash Player established TCP sessions to remote
hosts. A remote attacker could, consequently, use Flash Player to conduct a
DNS rebinding attack. (CVE-2007-5275, CVE-2008-1655)

A flaw was found in the way Flash Player restricted the interpretation and
usage of cross-domain policy files. A remote attacker could use Flash
Player to conduct cross-domain and cross-site scripting attacks.
(CVE-2007-6243, CVE-2008-1654)

A flaw was found in the way Flash Player interacted with web browsers. An
attacker could use malicious content presented by Flash Player to conduct a
cross-site scripting attack. (CVE-2007-6637)

All users of Adobe Flash Player should upgrade to this updated package,
which contains Flash Player version 9.0.124.0 and resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-08" />
        <updated date="2008-04-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5275.html">CVE-2007-5275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6243.html">CVE-2007-6243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6637.html">CVE-2007-6637</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6019.html">CVE-2007-6019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-0071.html">CVE-2007-0071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1655.html">CVE-2008-1655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1654.html">CVE-2008-1654</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3872.html">CVE-2008-3872</cve>
                <bugzilla href="http://bugzilla.redhat.com/367501" id="367501">CVE-2007-5275 Flash plugin DNS rebinding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440664" id="440664">CVE-2007-6243 Flash Player cross-domain and cross-site scripting flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440666" id="440666">CVE-2007-6637 Flash Player content injection flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440683" id="440683">CVE-2007-6019 Flash Player input validation error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440684" id="440684">CVE-2007-0071 Flash Player input validation error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440696" id="440696">CVE-2008-1655 Flash Player DNS rebind flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440698" id="440698">CVE-2008-1654 Flash Player cross domain HTTP header flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080221002" comment="flash-plugin is earlier than 0:9.0.124.0-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080221003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080222" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0222: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0222-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0222.html" />
          <reference source="CVE" ref_id="CVE-2008-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1380.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

A flaw was found in the processing of malformed JavaScript content. A web
page containing such malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-1380)

All Firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-16" />
        <updated date="2008-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1380.html">CVE-2008-1380</cve>
                <bugzilla href="http://bugzilla.redhat.com/440518" id="440518">CVE-2008-1380 Firefox JavaScript garbage collection crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080222004" comment="firefox-devel is earlier than 0:1.5.0.12-15.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103005" comment="firefox-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080222002" comment="firefox is earlier than 0:1.5.0.12-15.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080222007" comment="firefox is earlier than 0:1.5.0.12-0.15.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080223" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0223: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0223-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0223.html" />
          <reference source="CVE" ref_id="CVE-2008-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1380.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

A flaw was found in the processing of malformed JavaScript content. A web
page containing such malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-1380)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-16" />
        <updated date="2008-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1380.html">CVE-2008-1380</cve>
                <bugzilla href="http://bugzilla.redhat.com/440518" id="440518">CVE-2008-1380 Firefox JavaScript garbage collection crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223016" comment="seamonkey-nspr is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223020" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223006" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223010" comment="seamonkey-mail is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223002" comment="seamonkey is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223004" comment="seamonkey-devel is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223018" comment="seamonkey-nss is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223014" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223012" comment="seamonkey-chat is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223008" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223026" comment="seamonkey-nspr is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223028" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223027" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223030" comment="seamonkey-mail is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223023" comment="seamonkey is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223032" comment="seamonkey-devel is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223029" comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223025" comment="seamonkey-nss is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223024" comment="seamonkey-chat is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080223031" comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080224" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0224: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0224-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0224.html" />
          <reference source="CVE" ref_id="CVE-2008-1380" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1380.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

A flaw was found in the processing of malformed JavaScript content. An HTML
mail message containing such malicious content could cause Thunderbird to
crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-1380)

Note: JavaScript support is disabled by default in Thunderbird; the above
issue is not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-30" />
        <updated date="2008-04-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1380.html">CVE-2008-1380</cve>
                <bugzilla href="http://bugzilla.redhat.com/440518" id="440518">CVE-2008-1380 Firefox JavaScript garbage collection crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080224002" comment="thunderbird is earlier than 0:1.5.0.12-12.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080224005" comment="thunderbird is earlier than 0:1.5.0.12-11.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080233" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0233: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0233-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0233.html" />
          <reference source="CVE" ref_id="CVE-2007-5498" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5498.html" />
          <reference source="CVE" ref_id="CVE-2008-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0007.html" />
          <reference source="CVE" ref_id="CVE-2008-1367" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1367.html" />
          <reference source="CVE" ref_id="CVE-2008-1375" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1375.html" />
          <reference source="CVE" ref_id="CVE-2008-1619" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1619.html" />
          <reference source="CVE" ref_id="CVE-2008-1669" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1669.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* the absence of a protection mechanism when attempting to access a
critical section of code has been found in the Linux kernel open file
descriptors control mechanism, fcntl. This could allow a local unprivileged
user to simultaneously execute code, which would otherwise be protected
against parallel execution. As well, a race condition when handling locks
in the Linux kernel fcntl functionality, may have allowed a process
belonging to a local unprivileged user to gain re-ordered access to the
descriptor table. (CVE-2008-1669, Important)

* a possible hypervisor panic was found in the Linux kernel. A privileged
user of a fully virtualized guest could initiate a stress-test File
Transfer Protocol (FTP) transfer between the guest and the hypervisor,
possibly leading to hypervisor panic. (CVE-2008-1619, Important)

* the absence of a protection mechanism when attempting to access a
critical section of code, as well as a race condition, have been found
in the Linux kernel file system event notifier, dnotify. This could allow a
local unprivileged user to get inconsistent data, or to send arbitrary
signals to arbitrary system processes. (CVE-2008-1375, Important)

Red Hat would like to thank Nick Piggin for responsibly disclosing the
following issue:

* when accessing kernel memory locations, certain Linux kernel drivers
registering a fault handler did not perform required range checks. A local
unprivileged user could use this flaw to gain read or write access to
arbitrary kernel memory, or possibly cause a kernel crash.
(CVE-2008-0007, Important)

* the absence of sanity-checks was found in the hypervisor block backend
driver, when running 32-bit paravirtualized guests on a 64-bit host. The
number of blocks to be processed per one request from guest to host, or
vice-versa, was not checked for its maximum value, which could have allowed
a local privileged user of the guest operating system to cause a denial of
service. (CVE-2007-5498, Important)

* it was discovered that the Linux kernel handled string operations in the
opposite way to the GNU Compiler Collection (GCC). This could allow a local
unprivileged user to cause memory corruption. (CVE-2008-1367, Low)

As well, these updated packages fix the following bugs:

* on IBM System z architectures, when running QIOASSIST enabled QDIO
devices in an IBM z/VM environment, the output queue stalled under heavy
load. This caused network performance to degrade, possibly causing network
hangs and outages.

* multiple buffer overflows were discovered in the neofb video driver. It
was not possible for an unprivileged user to exploit these issues, and as
such, they have not been handled as security issues.

* when running Microsoft Windows in a HVM, a bug in vmalloc/vfree caused
network performance to degrade.

* on certain architectures, a bug in the libATA sata_nv driver may have
caused infinite reboots, and an "ata1: CPB flags CMD err flags 0x11" error.

* repeatedly hot-plugging a PCI Express card may have caused "Bad DLLP"
errors.

* a NULL pointer dereference in NFS, which may have caused applications to
crash, has been resolved.

* when attempting to kexec reboot, either manually or via a panic-triggered
kdump, the Unisys ES7000/one hanged after rebooting in the new kernel,
after printing the "Memory: 32839688k/33685504k available" line.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-07" />
        <updated date="2008-05-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5498.html">CVE-2007-5498</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0007.html">CVE-2008-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1367.html">CVE-2008-1367</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1375.html">CVE-2008-1375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1619.html">CVE-2008-1619</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1669.html">CVE-2008-1669</cve>
                <bugzilla href="http://bugzilla.redhat.com/369531" id="369531">CVE-2007-5498 missing sanity check in xen block backend driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/412071" id="412071">LTC37008-QDIO based network connections hang with QIOASSIST ON</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427400" id="427400">CVE-2008-1619 [xen-ia64] Dom0 panic while we run ftp test tool between HVM and Dom0.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428961" id="428961">CVE-2008-0007 kernel: insufficient range checks in fault handlers with mremap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433616" id="433616">[Xen] vmalloc/vfree on HVM Guest/IA64 does untolerate performance.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433617" id="433617">libata: sata_nv may send commands with duplicate tags [5.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437312" id="437312">CVE-2008-1367 Kernel doesn't clear DF for signal handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437770" id="437770">CVE-2008-1619 [xen-ia64] Dom0 panic while we run ftp test tool between HVM and Dom0.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439754" id="439754">CVE-2008-1375 kernel: race condition in dnotify (local DoS, local roothole possible)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440438" id="440438">[5.1] PCI Express hotplug driver problem (Bad DLLP) [rhel-5.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440447" id="440447">2.6.18-53.1.12 crashes on NULL pointer dereference with NFS on the stack [rhel-5.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442922" id="442922">kexec or kdump hangs on ES7000/ONE</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443433" id="443433">CVE-2008-1669 kernel: add rcu_read_lock() to fcheck() in both dnotify, locks.c and fix fcntl store/load race in locks.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233004" comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233002" comment="kernel is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233024" comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233022" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233014" comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233010" comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233018" comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233006" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233008" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233020" comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233016" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080233012" comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080235" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0235: speex security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0235-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0235.html" />
          <reference source="CVE" ref_id="CVE-2008-1686" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1686.html" />
    
    <description>Speex is a patent-free compression format designed especially for speech.
The Speex package contains a library for handling Speex files and sample
encoder and decoder implementations using this library.

The Speex library was found to not properly validate input values read from
the Speex files headers. An attacker could create a malicious Speex file
that would crash an application or, possibly, allow arbitrary code
execution with the privileges of the application calling the Speex library.
(CVE-2008-1686)

All users of speex are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-16" />
        <updated date="2008-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1686.html">CVE-2008-1686</cve>
                <bugzilla href="http://bugzilla.redhat.com/441239" id="441239">CVE-2008-1686 speex, libfishsound: insufficient boundary checks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080235004" comment="speex-devel is earlier than 0:1.0.5-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080235005" comment="speex-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080235002" comment="speex is earlier than 0:1.0.5-4.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080235003" comment="speex is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080235009" comment="speex-devel is earlier than 0:1.0.4-4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080235010" comment="speex-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080235007" comment="speex is earlier than 0:1.0.4-4.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080235008" comment="speex is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080237" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0237: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0237-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0237.html" />
          <reference source="CVE" ref_id="CVE-2005-0504" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0504.html" />
          <reference source="CVE" ref_id="CVE-2007-6282" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6282.html" />
          <reference source="CVE" ref_id="CVE-2008-0007" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0007.html" />
          <reference source="CVE" ref_id="CVE-2008-1375" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1375.html" />
          <reference source="CVE" ref_id="CVE-2008-1615" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1615.html" />
          <reference source="CVE" ref_id="CVE-2008-1669" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1669.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* the absence of a protection mechanism when attempting to access a
critical section of code has been found in the Linux kernel open file
descriptors control mechanism, fcntl. This could allow a local unprivileged
user to simultaneously execute code, which would otherwise be protected
against parallel execution. As well, a race condition when handling locks
in the Linux kernel fcntl functionality, may have allowed a process
belonging to a local unprivileged user to gain re-ordered access to the
descriptor table. (CVE-2008-1669, Important)

* on AMD64 architectures, the possibility of a kernel crash was discovered
by testing the Linux kernel process-trace ability. This could allow a local
unprivileged user to cause a denial of service (kernel crash).
(CVE-2008-1615, Important)

* the absence of a protection mechanism when attempting to access a
critical section of code, as well as a race condition, have been found
in the Linux kernel file system event notifier, dnotify. This could allow a
local unprivileged user to get inconsistent data, or to send arbitrary
signals to arbitrary system processes. (CVE-2008-1375, Important)

Red Hat would like to thank Nick Piggin for responsibly disclosing the
following issue:

* when accessing kernel memory locations, certain Linux kernel drivers
registering a fault handler did not perform required range checks. A local
unprivileged user could use this flaw to gain read or write access to
arbitrary kernel memory, or possibly cause a kernel crash.
(CVE-2008-0007, Important)

* the possibility of a kernel crash was found in the Linux kernel IPsec
protocol implementation, due to improper handling of fragmented ESP
packets. When an attacker controlling an intermediate router fragmented
these packets into very small pieces, it would cause a kernel crash on the
receiving node during packet reassembly. (CVE-2007-6282, Important)

* a flaw in the MOXA serial driver could allow a local unprivileged user
to perform privileged operations, such as replacing firmware.
(CVE-2005-0504, Important)

As well, these updated packages fix the following bugs:

* multiple buffer overflows in the neofb driver have been resolved. It was
not possible for an unprivileged user to exploit these issues, and as such,
they have not been handled as security issues.

* a kernel panic, due to inconsistent detection of AGP aperture size, has
been resolved.

* a race condition in UNIX domain sockets may have caused "recv()" to
return zero. In clustered configurations, this may have caused unexpected
failovers.

* to prevent link storms, network link carrier events were delayed by up to
one second, causing unnecessary packet loss. Now, link carrier events are
scheduled immediately.

* a client-side race on blocking locks caused large time delays on NFS file
systems.

* in certain situations, the libATA sata_nv driver may have sent commands
with duplicate tags, which were rejected by SATA devices. This may have
caused infinite reboots.

* running the "service network restart" command may have caused networking
to fail.

* a bug in NFS caused cached information about directories to be stored
for too long, causing wrong attributes to be read.

* on systems with a large highmem/lowmem ratio, NFS write performance may
have been very slow when using small files.

* a bug, which caused network hangs when the system clock was wrapped
around zero, has been resolved.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-07" />
        <updated date="2008-05-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0504.html">CVE-2005-0504</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6282.html">CVE-2007-6282</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0007.html">CVE-2008-0007</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1375.html">CVE-2008-1375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1615.html">CVE-2008-1615</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1669.html">CVE-2008-1669</cve>
                <bugzilla href="http://bugzilla.redhat.com/404291" id="404291">CVE-2007-6282 IPSec ESP kernel panics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/423111" id="423111">CVE-2005-0504 Buffer overflow in moxa driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428961" id="428961">CVE-2008-0007 kernel: insufficient range checks in fault handlers with mremap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431430" id="431430">CVE-2008-1615 kernel: ptrace: Unprivileged crash on x86_64 %cs corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435122" id="435122">[RHEL4.6] In unix domain sockets, recv() may incorrectly return zero</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436102" id="436102">Fake ARP dropped after migration leading to loss of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436129" id="436129">LTC41942-30 second flock() calls against files stored on a NetApp while using NFS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436499" id="436499">libata: sata_nv may send commands with duplicate tags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436749" id="436749">Network stack hang after service network restart</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437788" id="437788">NFS: Fix directory caching problem - with test case and patch.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438345" id="438345">[2.6.9-55.9] VM pagecache reclaim patch causes high latency on systems with large highmem/lowmem ratios</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438477" id="438477">Since "Patch2037: linux-2.6.9-vm-balance.patch" my NFS performance is poorly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439754" id="439754">CVE-2008-1375 kernel: race condition in dnotify (local DoS, local roothole possible)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443433" id="443433">CVE-2008-1669 kernel: add rcu_read_lock() to fcheck() in both dnotify, locks.c and fix fcntl store/load race in locks.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237002" comment="kernel is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237022" comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237004" comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237016" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237020" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237014" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237012" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237010" comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237008" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080237006" comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080238" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0238: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0238.html" />
          <reference source="CVE" ref_id="CVE-2008-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1693.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment, including kpdf, a PDF file viewer.

Kees Cook discovered a flaw in the way kpdf displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause kpdf to crash, or, potentially, execute arbitrary code when
opened. (CVE-2008-1693)

All kdegraphics users are advised to upgrade to these updated packages,
which contain backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-17" />
        <updated date="2008-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1693.html">CVE-2008-1693</cve>
                <bugzilla href="http://bugzilla.redhat.com/441722" id="441722">CVE-2008-1693 xpdf: embedded font vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080238002" comment="kdegraphics is earlier than 7:3.3.1-9.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080238003" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080238004" comment="kdegraphics-devel is earlier than 7:3.3.1-9.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080238005" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080239" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0239: poppler security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0239-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0239.html" />
          <reference source="CVE" ref_id="CVE-2008-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1693.html" />
    
    <description>Poppler is a PDF rendering library, used by applications such as Evince.

Kees Cook discovered a flaw in the way poppler displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause applications that use poppler -- such as Evince -- to crash,
or, potentially, execute arbitrary code when opened. (CVE-2008-1693)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-17" />
        <updated date="2008-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1693.html">CVE-2008-1693</cve>
                <bugzilla href="http://bugzilla.redhat.com/441722" id="441722">CVE-2008-1693 xpdf: embedded font vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080239004" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080239005" comment="poppler-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080239002" comment="poppler is earlier than 0:0.5.4-4.4.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080239003" comment="poppler is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080239006" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080239007" comment="poppler-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080240" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0240: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0240-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0240.html" />
          <reference source="CVE" ref_id="CVE-2008-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1693.html" />
    
    <description>Xpdf is an X Window System-based viewer for Portable Document Format (PDF)
files.

Kees Cook discovered a flaw in the way xpdf displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause xpdf to crash, or, potentially, execute arbitrary code when
opened. (CVE-2008-1693)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-17" />
        <updated date="2008-04-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1693.html">CVE-2008-1693</cve>
                <bugzilla href="http://bugzilla.redhat.com/441722" id="441722">CVE-2008-1693 xpdf: embedded font vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080240002" comment="xpdf is earlier than 1:3.00-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080240003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080243" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0243: java-1.4.2-bea security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0243-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0243.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
    
    <description>The BEA WebLogic JRockit 1.4.2_16 JRE and SDK contains BEA WebLogic JRockit
Virtual Machine 1.4.2_16 and is certified for the Java 2 Platform, Standard
Edition, v1.4.2.

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187)

Please note: This vulnerability can only be triggered in java-1.4.2-bea by
calling the "appletviewer" application.

All java-1.4.2-bea users should upgrade to this updated package which
addresses this vulnerability.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-28" />
        <updated date="2008-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
                <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080243004" comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100005" comment="java-1.4.2-bea-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080243002" comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100003" comment="java-1.4.2-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080243006" comment="java-1.4.2-bea-src is earlier than 0:1.4.2.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100007" comment="java-1.4.2-bea-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080243012" comment="java-1.4.2-bea-missioncontrol is earlier than 0:1.4.2.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100013" comment="java-1.4.2-bea-missioncontrol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080243010" comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100011" comment="java-1.4.2-bea-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080243008" comment="java-1.4.2-bea-demo is earlier than 0:1.4.2.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100009" comment="java-1.4.2-bea-demo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080244" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0244: java-1.5.0-bea security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0244-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0244.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
          <reference source="CVE" ref_id="CVE-2008-1193" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1193.html" />
          <reference source="CVE" ref_id="CVE-2008-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1194.html" />
    
    <description>The BEA WebLogic JRockit 1.5.0_14 JRE and SDK contain BEA WebLogic JRockit
Virtual Machine 1.5.0_14, and are certified for the Java 5 Platform,
Standard Edition, v1.5.0.

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187)

A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possibly execute
arbitrary code with the permissions of the user running the JRE.
(CVE-2008-1193)

A flaw was found in the JRE color management library. An untrusted
application or applet could trigger a denial of service (JVM crash).
(CVE-2008-1194)

The vulnerabilities concerning applets listed above can only be triggered
in java-1.5.0-bea, by calling the "appletviewer" application.

Users of java-1.5.0-bea are advised to upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-28" />
        <updated date="2008-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1193.html">CVE-2008-1193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1194.html">CVE-2008-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436296" id="436296">CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080244002" comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156003" comment="java-1.5.0-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080244012" comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156013" comment="java-1.5.0-bea-missioncontrol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080244010" comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156005" comment="java-1.5.0-bea-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080244004" comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156009" comment="java-1.5.0-bea-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080244006" comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156011" comment="java-1.5.0-bea-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080244008" comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156007" comment="java-1.5.0-bea-demo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080245" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0245: java-1.6.0-bea security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0245-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0245.html" />
          <reference source="CVE" ref_id="CVE-2008-0628" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0628.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
          <reference source="CVE" ref_id="CVE-2008-1193" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1193.html" />
          <reference source="CVE" ref_id="CVE-2008-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1194.html" />
    
    <description>The BEA WebLogic JRockit 1.6.0_03 JRE and SDK contain BEA WebLogic JRockit
Virtual Machine 1.6.0_03, and are certified for the Java 6 Platform,
Standard Edition, v1.6.0.

The Java XML parsing code processed external entity references even when
the "external general entities" property was set to "FALSE". This allowed
remote attackers to conduct XML External Entity (XXE) attacks, possibly
causing a denial of service, or gaining access to restricted resources.
(CVE-2008-0628)

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187)

A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possible execute
arbitrary code with the permissions of the user running the JRE.
(CVE-2008-1193)

A flaw was found in the JRE color management library. An untrusted
application or applet could trigger a denial of service (JVM crash).
(CVE-2008-1194)

The vulnerabilities concerning applets listed above can only be triggered
in java-1.6.0-bea, by calling the "appletviewer" application.

Users of java-1.6.0-bea are advised to upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-28" />
        <updated date="2008-04-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0628.html">CVE-2008-0628</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1193.html">CVE-2008-1193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1194.html">CVE-2008-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/431416" id="431416">CVE-2008-0628 java-1.6.0 default external entity processing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436296" id="436296">CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080245004" comment="java-1.6.0-bea-jdbc is earlier than 1:1.6.0.03-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245005" comment="java-1.6.0-bea-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080245006" comment="java-1.6.0-bea-devel is earlier than 1:1.6.0.03-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245007" comment="java-1.6.0-bea-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080245002" comment="java-1.6.0-bea is earlier than 1:1.6.0.03-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245003" comment="java-1.6.0-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080245010" comment="java-1.6.0-bea-src is earlier than 1:1.6.0.03-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245011" comment="java-1.6.0-bea-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080245008" comment="java-1.6.0-bea-missioncontrol is earlier than 1:1.6.0.03-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245009" comment="java-1.6.0-bea-missioncontrol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080245012" comment="java-1.6.0-bea-demo is earlier than 1:1.6.0.03-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245013" comment="java-1.6.0-bea-demo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080262" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0262: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0262-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0262.html" />
          <reference source="CVE" ref_id="CVE-2008-1693" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1693.html" />
    
    <description>gpdf is a GNOME-based viewer for Portable Document Format (PDF) files.

Kees Cook discovered a flaw in the way gpdf displayed malformed fonts
embedded in PDF files. An attacker could create a malicious PDF file that
would cause gpdf to crash, or, potentially, execute arbitrary code when
opened. (CVE-2008-1693)

Users of gpdf are advised to upgrade to this updated package, which
contains a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-08" />
        <updated date="2008-05-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1693.html">CVE-2008-1693</cve>
                <bugzilla href="http://bugzilla.redhat.com/441722" id="441722">CVE-2008-1693 xpdf: embedded font vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080262002" comment="gpdf is earlier than 0:2.8.2-7.7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080262003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080267" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0267: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0267.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
          <reference source="CVE" ref_id="CVE-2008-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1188.html" />
          <reference source="CVE" ref_id="CVE-2008-1189" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1189.html" />
          <reference source="CVE" ref_id="CVE-2008-1190" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1190.html" />
          <reference source="CVE" ref_id="CVE-2008-1191" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1191.html" />
          <reference source="CVE" ref_id="CVE-2008-1192" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1192.html" />
          <reference source="CVE" ref_id="CVE-2008-1193" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1193.html" />
          <reference source="CVE" ref_id="CVE-2008-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1194.html" />
          <reference source="CVE" ref_id="CVE-2008-1195" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1195.html" />
          <reference source="CVE" ref_id="CVE-2008-1196" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1196.html" />
    
    <description>IBM's 1.6.0 Java release includes the IBM Java 2 Runtime Environment, and
the IBM Java 2 Software Development Kit.

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187) 

Several buffer overflow flaws were found in Java Web Start (JWS). An
untrusted JNLP application could access local files, or execute local
applications accessible to the user running the JRE. (CVE-2008-1188,
CVE-2008-1189, CVE-2008-1190, CVE-2008-1191, CVE-2008-1196)

A flaw was found in the Java plug-in. A remote attacker could bypass the
same origin policy, executing arbitrary code with the permissions of the
user running the JRE. (CVE-2008-1192)

A flaw was found in the JRE image parsing libraries. An untrusted
application or applet could cause a denial of service, or possibly execute
arbitrary code with the permissions of the user running the JRE.
(CVE-2008-1193)

A flaw was found in the JRE color management library. An untrusted
application or applet could trigger a denial of service (JVM crash).
(CVE-2008-1194)

The JRE allowed untrusted JavaScript code to create local network
connections by the use of Java APIs. A remote attacker could use these
flaws to access local network services. (CVE-2008-1195)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, that contain IBM's 1.6.0 SR1 Java release, which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-19" />
        <updated date="2008-05-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1188.html">CVE-2008-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1189.html">CVE-2008-1189</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1190.html">CVE-2008-1190</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1191.html">CVE-2008-1191</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1192.html">CVE-2008-1192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1193.html">CVE-2008-1193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1194.html">CVE-2008-1194</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1195.html">CVE-2008-1195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1196.html">CVE-2008-1196</cve>
                <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436293" id="436293">CVE-2008-1188 Buffer overflow security vulnerabilities in Java Web Start (CVE-2008-1189, CVE-2008-1190)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436295" id="436295">CVE-2008-1192 Java Plugin same-origin-policy bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436296" id="436296">CVE-2008-1193 JRE image parsing library allows privilege escalation (CVE-2008-1194)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436299" id="436299">CVE-2008-1195 Java-API calls in untrusted Javascript allow network privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436302" id="436302">CVE-2008-1196 Buffer overflow security vulnerabilities in Java Web Start</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444746" id="444746">CVE-2008-1191 Untrusted Java Web Start arbitrary file creation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267014" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267015" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267016" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267017" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267008" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267009" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267012" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267013" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267004" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267005" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267006" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267007" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080267010" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.1-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267011" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080270" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0270: libvorbis security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0270-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0270.html" />
          <reference source="CVE" ref_id="CVE-2008-1419" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1419.html" />
          <reference source="CVE" ref_id="CVE-2008-1420" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1420.html" />
          <reference source="CVE" ref_id="CVE-2008-1423" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1423.html" />
    
    <description>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

Will Drewry of the Google Security Team reported several flaws in the way
libvorbis processed audio data. An attacker could create a carefully
crafted OGG audio file in such a way that it could cause an application
linked with libvorbis to crash, or execute arbitrary code when it was
opened. (CVE-2008-1419, CVE-2008-1420, CVE-2008-1423)

Moreover, additional OGG file sanity-checks have been added to prevent
possible exploitation of similar issues in the future.

Users of libvorbis are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-14" />
        <updated date="2008-05-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1419.html">CVE-2008-1419</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1420.html">CVE-2008-1420</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1423.html">CVE-2008-1423</cve>
                <bugzilla href="http://bugzilla.redhat.com/440700" id="440700">CVE-2008-1419 vorbis: zero-dim codebooks can cause crash, infinite loop or heap overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440706" id="440706">CVE-2008-1420 vorbis: integer overflow in partvals computation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440709" id="440709">CVE-2008-1423 vorbis: integer oveflow caused by huge codebooks</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080270004" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080270005" comment="libvorbis-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080270002" comment="libvorbis is earlier than 1:1.1.2-3.el5_1.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080270003" comment="libvorbis is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080270009" comment="libvorbis-devel is earlier than 1:1.0-10.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080270010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080270007" comment="libvorbis is earlier than 1:1.0-10.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080270008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080270013" comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080270010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080270012" comment="libvorbis is earlier than 1:1.1.0-3.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080270008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080275" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0275: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0275-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0275.html" />
          <reference source="CVE" ref_id="CVE-2007-5093" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5093.html" />
          <reference source="CVE" ref_id="CVE-2007-6282" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6282.html" />
          <reference source="CVE" ref_id="CVE-2007-6712" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6712.html" />
          <reference source="CVE" ref_id="CVE-2008-1615" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1615.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* on AMD64 architectures, the possibility of a kernel crash was discovered
by testing the Linux kernel process-trace ability. This could allow a local
unprivileged user to cause a denial of service (kernel crash).
(CVE-2008-1615, Important)

* on 64-bit architectures, the possibility of a timer-expiration value
overflow was found in the Linux kernel high-resolution timers
functionality, hrtimer. This could allow a local unprivileged user to setup
a large interval value, forcing the timer expiry value to become negative,
causing a denial of service (kernel hang). (CVE-2007-6712, Important)

* the possibility of a kernel crash was found in the Linux kernel IPsec
protocol implementation, due to improper handling of fragmented ESP
packets. When an attacker controlling an intermediate router fragmented
these packets into very small pieces, it would cause a kernel crash on the
receiving node during packet reassembly. (CVE-2007-6282, Important)

* a potential denial of service attack was discovered in the Linux kernel
PWC USB video driver. A local unprivileged user could use this flaw to
bring the kernel USB subsystem into the busy-waiting state, causing a
denial of service. (CVE-2007-5093, Low)

As well, these updated packages fix the following bugs:

* in certain situations, a kernel hang and a possible panic occurred when
disabling the cpufreq daemon. This may have prevented system reboots from
completing successfully.

* continual "softlockup" messages, which occurred on the guest's console
after a successful save and restore of a Red Hat Enterprise Linux 5
para-virtualized guest, have been resolved.

* in the previous kernel packages, the kernel may not have reclaimed NFS
locks after a system reboot.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5093.html">CVE-2007-5093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6282.html">CVE-2007-6282</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6712.html">CVE-2007-6712</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1615.html">CVE-2008-1615</cve>
                <bugzilla href="http://bugzilla.redhat.com/306591" id="306591">CVE-2007-5093 kernel PWC driver DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/400821" id="400821">rhel5.1s2 hang at 'Disabling ondemand cpu frequency scaling' [rhel-5.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/404291" id="404291">CVE-2007-6282 IPSec ESP kernel panics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429516" id="429516">booting with maxcpus=1 panics when starting cpufreq service [rhel-5.1.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431430" id="431430">CVE-2008-1615 kernel: ptrace: Unprivileged crash on x86_64 %cs corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439999" id="439999">CVE-2007-6712 kernel: infinite loop in highres timers (kernel hang)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444402" id="444402">[RHEL5]: Softlockup after save/restore in PV guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445360" id="445360">RHEL5.1 kernel not reclaiming NFS locks when server reboots</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275004" comment="kernel-headers is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275002" comment="kernel is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275024" comment="kernel-doc is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275020" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275012" comment="kernel-devel is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275008" comment="kernel-debug is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275016" comment="kernel-kdump is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275006" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275014" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275022" comment="kernel-PAE is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275018" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080275010" comment="kernel-xen is earlier than 0:2.6.18-53.1.21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080287" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0287: libxslt security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0287-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0287.html" />
          <reference source="CVE" ref_id="CVE-2008-1767" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1767.html" />
    
    <description>libxslt is a C library, based on libxml, for parsing of XML files into
other textual formats (eg HTML, plain text and other XML representations of
the underlying data). It uses the standard XSLT stylesheet transformation
mechanism and, being written in plain ANSI C, is designed to be simple to
incorporate into other applications

Anthony de Almeida Lopes reported the libxslt library did not properly
process long "transformation match" conditions in the XSL stylesheet files.
An attacker could create a malicious XSL file that would cause a crash, or,
possibly, execute and arbitrary code with the privileges of the application
using libxslt library to perform XSL transformations. (CVE-2008-1767)

All users are advised to upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-21" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1767.html">CVE-2008-1767</cve>
                <bugzilla href="http://bugzilla.redhat.com/446809" id="446809">CVE-2008-1767 libxslt: fixed-sized steps array overflow via "template match" condition in XSL file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287006" comment="libxslt-devel is earlier than 0:1.1.17-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287007" comment="libxslt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287004" comment="libxslt-python is earlier than 0:1.1.17-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287005" comment="libxslt-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287002" comment="libxslt is earlier than 0:1.1.17-2.el5_1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287003" comment="libxslt is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287013" comment="libxslt-devel is earlier than 0:1.0.33-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287014" comment="libxslt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287011" comment="libxslt-python is earlier than 0:1.0.33-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287012" comment="libxslt-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287009" comment="libxslt is earlier than 0:1.0.33-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287010" comment="libxslt is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287018" comment="libxslt-python is earlier than 0:1.1.11-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287012" comment="libxslt-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287017" comment="libxslt-devel is earlier than 0:1.1.11-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287014" comment="libxslt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080287016" comment="libxslt is earlier than 0:1.1.11-1.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287010" comment="libxslt is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080288" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0288: samba security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0288-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0288.html" />
          <reference source="CVE" ref_id="CVE-2008-1105" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1105.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A heap-based buffer overflow flaw was found in the way Samba clients handle
over-sized packets. If a client connected to a malicious Samba server, it
was possible to execute arbitrary code as the Samba client user. It was
also possible for a remote user to send a specially crafted print request
to a Samba server that could result in the server executing the vulnerable
client code, resulting in arbitrary code execution with the permissions of
the Samba server. (CVE-2008-1105)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-28" />
        <updated date="2008-05-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1105.html">CVE-2008-1105</cve>
                <bugzilla href="http://bugzilla.redhat.com/446724" id="446724">CVE-2008-1105 Samba client buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288008" comment="samba-client is earlier than 0:3.0.9-1.3E.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288009" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288006" comment="samba-common is earlier than 0:3.0.9-1.3E.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288002" comment="samba is earlier than 0:3.0.9-1.3E.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288004" comment="samba-swat is earlier than 0:3.0.9-1.3E.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288014" comment="samba-client is earlier than 0:3.0.25b-1.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288009" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288012" comment="samba-common is earlier than 0:3.0.25b-1.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288007" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288011" comment="samba is earlier than 0:3.0.25b-1.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080288013" comment="samba-swat is earlier than 0:3.0.25b-1.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080288005" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080290" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0290: samba security and bug fix update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0290-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0290.html" />
          <reference source="CVE" ref_id="CVE-2008-1105" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1105.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A heap-based buffer overflow flaw was found in the way Samba clients handle
over-sized packets. If a client connected to a malicious Samba server, it
was possible to execute arbitrary code as the Samba client user. It was
also possible for a remote user to send a specially crafted print request
to a Samba server that could result in the server executing the vulnerable
client code, resulting in arbitrary code execution with the permissions of
the Samba server. (CVE-2008-1105)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

This update also addresses two issues which prevented Samba from joining
certain Windows domains with tightened security policies, and prevented
certain signed SMB content from working as expected:

* when some Windows® 2000-based domain controllers were set to use
mandatory signing, Samba clients would drop the connection because of an
error when generating signatures. This presented as a "Server packet had
invalid SMB signature" error to the Samba client. This update corrects the
signature generation error.

* Samba servers using the "net ads join" command to connect to a Windows
Server® 2003-based domain would fail with "failed to get schannel session
key from server" and "NT_STATUS_ACCESS_DENIED" errors. This update
correctly binds to the NETLOGON share, allowing Samba servers to connect to
the domain properly.

Users of Samba are advised to upgrade to these updated packages, which
contain a backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-28" />
        <updated date="2008-05-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1105.html">CVE-2008-1105</cve>
                <bugzilla href="http://bugzilla.redhat.com/444637" id="444637">Join fails with stricter w2k3 security options set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446724" id="446724">CVE-2008-1105 Samba client buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447380" id="447380">Signing issue: "Server packet had invalid SMB signature" with some Win2K servers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080290008" comment="samba-client is earlier than 0:3.0.28-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080290009" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080290006" comment="samba-common is earlier than 0:3.0.28-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080290007" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080290002" comment="samba is earlier than 0:3.0.28-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080290003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080290004" comment="samba-swat is earlier than 0:3.0.28-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080290005" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080295" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0295: vsftpd security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0295-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0295.html" />
          <reference source="CVE" ref_id="CVE-2007-5962" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5962.html" />
    
    <description>The vsftpd package includes a Very Secure File Transfer Protocol (FTP)
daemon.

A memory leak was discovered in the vsftpd daemon. An attacker who is able
to connect to an FTP service, either as an authenticated or anonymous user,
could cause vsftpd to allocate all available memory if the "deny_file"
option was enabled in vsftpd.conf. (CVE-2007-5962)

As well, this updated package fixes following bugs:

* a race condition could occur even when the "lock_upload_files" option is
set. When uploading two files simultaneously, the result was a combination
of the two files. This resulted in uploaded files becoming corrupted. In
these updated packages, uploading two files simultaneously will result in a
file that is identical to the last uploaded file.

* when the "userlist_enable" option is used, failed log in attempts as a
result of the user not being in the list of allowed users, or being in the
list of denied users, will not be logged. In these updated packages, a new
"userlist_log=YES" option can be configured in vsftpd.conf, which will log
failed log in attempts in these situations.

* vsftpd did not support usernames that started with an underscore or a
period character. Usernames starting with an underscore or a period are
supported in these updated packages.

* using wildcards in conjunction with the "ls" command did not return all
the file names it should. For example, if you FTPed into a directory
containing three files -- A1, A21 and A11 -- and ran the "ls *1" command,
only the file names A1 and A21 were returned. These updated packages use
greedier code that continues to speculatively scan for items even after
matches have been found.

* when the "user_config_dir" option is enabled in vsftpd.conf, and the
user-specific configuration file did not exist, the following error
occurred after a user entered their password during the log in process:

500 OOPS: reading non-root config file

This has been resolved in this updated package.

All vsftpd users are advised to upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-21" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5962.html">CVE-2007-5962</cve>
                <bugzilla href="http://bugzilla.redhat.com/240553" id="240553">vsftpd has a create/lock race condition which corrupts uploads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/392181" id="392181">vsftpd file listing issue with wildcard</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/392231" id="392231">Uploaded file corrupted when two connections from same client uploading same file simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/397011" id="397011">CVE-2007-5962 vsftpd: memory leak when deny_file option is set</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/400921" id="400921">OOPS: reading non-root config file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080295002" comment="vsftpd is earlier than 0:2.0.5-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080295003" comment="vsftpd is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080297" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0297: dovecot security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0297-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0297.html" />
          <reference source="CVE" ref_id="CVE-2007-2231" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2231.html" />
          <reference source="CVE" ref_id="CVE-2007-4211" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4211.html" />
          <reference source="CVE" ref_id="CVE-2007-6598" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6598.html" />
          <reference source="CVE" ref_id="CVE-2008-1199" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1199.html" />
    
    <description>Dovecot is an IMAP server for Linux and UNIX-like systems, primarily
written with security in mind.

A flaw was discovered in the way Dovecot handled the "mail_extra_groups"
option. An authenticated attacker with local shell access could leverage
this flaw to read, modify, or delete other users mail that is stored on
the mail server. (CVE-2008-1199)

This issue did not affect the default Red Hat Enterprise Linux 5 Dovecot
configuration. This update adds two new configuration options --
"mail_privileged_group" and "mail_access_groups" -- to minimize the usage
of additional privileges.

A directory traversal flaw was discovered in Dovecot's zlib plug-in. An
authenticated user could use this flaw to view other compressed mailboxes
with the permissions of the Dovecot process. (CVE-2007-2231)

A flaw was found in the Dovecot ACL plug-in. User with only insert
permissions for a mailbox could use the "COPY" and "APPEND" commands to set
additional message flags. (CVE-2007-4211)

A flaw was found in a way Dovecot cached LDAP query results in certain
configurations. This could possibly allow authenticated users to log in as
a different user who has the same password. (CVE-2007-6598)

As well, this updated package fixes the following bugs:

* configuring "userdb" and "passdb" to use LDAP caused Dovecot to hang. A
segmentation fault may have occurred. In this updated package, using an
LDAP backend for "userdb" and "passdb" no longer causes Dovecot to hang.

* the Dovecot "login_process_size" limit was configured for 32-bit systems.
On 64-bit systems, when Dovecot was configured to use either IMAP or POP3,
the log in processes crashed with out-of-memory errors. Errors such as the
following were logged:

pop3-login: pop3-login: error while loading shared libraries:
libsepol.so.1: failed to map segment from shared object: Cannot allocate
memory

In this updated package, the "login_process_size" limit is correctly
configured on 64-bit systems, which resolves this issue.

Note: this updated package upgrades dovecot to version 1.0.7. For
further details, refer to the Dovecot changelog:
http://koji.fedoraproject.org/koji/buildinfo?buildID=23397

Users of dovecot are advised to upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2231.html">CVE-2007-2231</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4211.html">CVE-2007-4211</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6598.html">CVE-2007-6598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1199.html">CVE-2008-1199</cve>
                <bugzilla href="http://bugzilla.redhat.com/238439" id="238439">CVE-2007-2231 Directory traversal in dovecot with zlib plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/245249" id="245249">Dovecot hangs while using ldap backend.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251007" id="251007">CVE-2007-4211 Dovecot possible privilege ascalation in ACL plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253363" id="253363">Dovecot pop3-login/imap-login crash with OOM error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/331441" id="331441">Please consider upgrading Dovecot to 1.0rc23 at least</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/380401" id="380401">tracker bug for 1.0.7 rebase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427575" id="427575">CVE-2007-6598 dovecot LDAP+auth cache user login mixup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436927" id="436927">CVE-2008-1199 dovecot: insecure mail_extra_groups option</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080297002" comment="dovecot is earlier than 0:1.0.7-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080297003" comment="dovecot is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080300" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0300: bind security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0300-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0300.html" />
          <reference source="CVE" ref_id="CVE-2007-6283" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6283.html" />
          <reference source="CVE" ref_id="CVE-2008-0122" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0122.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

It was discovered that the bind packages created the "rndc.key" file with
insecure file permissions. This allowed any local user to read the content
of this file. A local user could use this flaw to control some aspects of
the named daemon by using the rndc utility, for example, stopping the named
daemon. This problem did not affect systems with the bind-chroot package
installed. (CVE-2007-6283)

A buffer overflow flaw was discovered in the "inet_network()" function, as
implemented by libbind. An attacker could use this flaw to crash an
application calling this function, with an argument provided from an
untrusted source. (CVE-2008-0122)

As well, these updated packages fix the following bugs:

* when using an LDAP backend, missing function declarations caused
segmentation faults, due to stripped pointers on machines where pointers
are longer than integers.

* starting named may have resulted in named crashing, due to a race
condition during D-BUS connection initialization. This has been resolved in
these updated packages.

* the named init script returned incorrect error codes, causing the
"status" command to return an incorrect status. In these updated packages,
the named init script is Linux Standard Base (LSB) compliant.

* in these updated packages, the "rndc [command] [zone]" command, where
[command] is an rndc command, and [zone] is the specified zone, will find
the [zone] if the zone is unique to all views.

* the default named log rotation script did not work correctly when using
the bind-chroot package. In these updated packages, installing
bind-chroot creates the symbolic link "/var/log/named.log", which points
to "/var/named/chroot/var/log/named.log", which resolves this issue.

* a previous bind update incorrectly changed the permissions on the
"/etc/openldap/schema/dnszone.schema" file to mode 640, instead of mode
644, which resulted in OpenLDAP not being able to start. In these updated
packages, the permissions are correctly set to mode 644.

* the "checkconfig" parameter was missing in the named usage report. For
example, running the "service named" command did not return "checkconfig"
in the list of available options.

* due to a bug in the named init script not handling the rndc return value
correctly, the "service named stop" and "service named restart" commands
failed on certain systems.

* the bind-chroot spec file printed errors when running the "%pre" and
"%post" sections. Errors such as the following occurred:

Locating //etc/named.conf failed:
[FAILED]

This has been resolved in these updated packages.

* installing the bind-chroot package creates a "/dev/random" file in the
chroot environment; however, the "/dev/random" file had an incorrect
SELinux label. Starting named resulted in an 'avc: denied { getattr } for
pid=[pid] comm="named" path="/dev/random"' error being logged. The
"/dev/random" file has the correct SELinux label in these updated packages.

* in certain situations, running the "bind +trace" command resulted in
random segmentation faults.

As well, these updated packages add the following enhancements:

* support has been added for GSS-TSIG (RFC 3645).

* the "named.root" file has been updated to reflect the new address for
L.ROOT-SERVERS.NET.

* updates BIND to the latest 9.3 maintenance release.

All users of bind are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6283.html">CVE-2007-6283</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0122.html">CVE-2008-0122</cve>
                <bugzilla href="http://bugzilla.redhat.com/240788" id="240788">bind_sdb, ldap2zone segfaulting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240876" id="240876">bind crashes on restart and also when running without forwarders</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242734" id="242734">Wrong init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247486" id="247486">bind-chroot does not modify /etc/logrotate.d/named</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250118" id="250118">dnszone.schema bad file permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250744" id="250744">missed parameter "configtest" in init script usage report</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250901" id="250901">"service named restart" fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251528" id="251528">RFE: add support for GSSTSIG</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252334" id="252334">bind-chroot-9.3.3-9.0.1 leaks error noise in its scripts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253537" id="253537">avc:  denied  { getattr } for comm="named" path="/dev/random"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/353741" id="353741">Rebase to latest 9.3 maintenance release</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/363531" id="363531">New L.ROOT-SERVERS.NET address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/419421" id="419421">CVE-2007-6283 bind: /etc/rndc.key has 644 permissions by default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/423741" id="423741">resolver library causes segfaults in bind-utils such as dig,ping</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429149" id="429149">CVE-2008-0122 libbind off-by-one buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300016" comment="bind-utils is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300017" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300014" comment="bind-chroot is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300015" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300006" comment="bind-libbind-devel is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300007" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300004" comment="bind-devel is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300005" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300008" comment="bind-sdb is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300009" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300002" comment="bind is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300010" comment="bind-libs is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300011" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080300012" comment="caching-nameserver is earlier than 30:9.3.4-6.P1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300013" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080364" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0364: mysql security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0364-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0364.html" />
          <reference source="CVE" ref_id="CVE-2006-0903" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-0903.html" />
          <reference source="CVE" ref_id="CVE-2006-4031" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4031.html" />
          <reference source="CVE" ref_id="CVE-2006-4227" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4227.html" />
          <reference source="CVE" ref_id="CVE-2006-7232" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7232.html" />
          <reference source="CVE" ref_id="CVE-2007-1420" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1420.html" />
          <reference source="CVE" ref_id="CVE-2007-2583" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2583.html" />
          <reference source="CVE" ref_id="CVE-2007-2691" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2691.html" />
          <reference source="CVE" ref_id="CVE-2007-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2692.html" />
          <reference source="CVE" ref_id="CVE-2007-3781" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3781.html" />
          <reference source="CVE" ref_id="CVE-2007-3782" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3782.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld), and
many different client programs and libraries.

MySQL did not require privileges such as "SELECT" for the source table in a
"CREATE TABLE LIKE" statement. An authenticated user could obtain sensitive
information, such as the table structure. (CVE-2007-3781)

A flaw was discovered in MySQL that allowed an authenticated user to gain
update privileges for a table in another database, via a view that refers
to the external table. (CVE-2007-3782)

MySQL did not require the "DROP" privilege for "RENAME TABLE" statements.
An authenticated user could use this flaw to rename arbitrary tables.
(CVE-2007-2691)

A flaw was discovered in the mysql_change_db function when returning from
SQL SECURITY INVOKER stored routines. An authenticated user could use this
flaw to gain database privileges. (CVE-2007-2692)

MySQL allowed an authenticated user to bypass logging mechanisms via SQL
queries that contain the NULL character, which were not properly handled by
the mysql_real_query function. (CVE-2006-0903)

MySQL allowed an authenticated user to access a table through a previously
created MERGE table, even after the user's privileges were revoked from
the original table, which might violate intended security policy. This is
addressed by allowing the MERGE storage engine to be disabled, which can
be done by running mysqld with the "--skip-merge" option. (CVE-2006-4031)

MySQL evaluated arguments in the wrong security context, which allowed an
authenticated user to gain privileges through a routine that had been made
available using "GRANT EXECUTE". (CVE-2006-4227)

Multiple flaws in MySQL allowed an authenticated user to cause the MySQL
daemon to crash via crafted SQL queries. This only caused a temporary
denial of service, as the MySQL daemon is automatically restarted after the
crash. (CVE-2006-7232, CVE-2007-1420, CVE-2007-2583)

As well, these updated packages fix the following bugs:

* a separate counter was used for "insert delayed" statements, which caused
rows to be discarded. In these updated packages, "insert delayed"
statements no longer use a separate counter, which resolves this issue.

* due to a bug in the Native POSIX Thread Library, in certain situations,
"flush tables" caused a deadlock on tables that had a read lock. The mysqld
daemon had to be killed forcefully. Now, "COND_refresh" has been replaced
with "COND_global_read_lock", which resolves this issue.

* mysqld crashed if a query for an unsigned column type contained a
negative value for a "WHERE [column] NOT IN" subquery.

* in master and slave server situations, specifying "on duplicate key
update" for "insert" statements did not update slave servers.

* in the mysql client, empty strings were displayed as "NULL". For
example, running "insert into [table-name] values (' ');" resulted in a
"NULL" entry being displayed when querying the table using "select * from
[table-name];".

* a bug in the optimizer code resulted in certain queries executing much
slower than expected.

* on 64-bit PowerPC architectures, MySQL did not calculate the thread stack
size correctly, which could have caused MySQL to crash when overly-complex
queries were used.

Note: these updated packages upgrade MySQL to version 5.0.45. For a full
list of bug fixes and enhancements, refer to the MySQL release notes:
http://dev.mysql.com/doc/refman/5.0/en/releasenotes-cs-5-0.html

All mysql users are advised to upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-0903.html">CVE-2006-0903</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4031.html">CVE-2006-4031</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4227.html">CVE-2006-4227</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7232.html">CVE-2006-7232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1420.html">CVE-2007-1420</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2583.html">CVE-2007-2583</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2691.html">CVE-2007-2691</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2692.html">CVE-2007-2692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3781.html">CVE-2007-3781</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3782.html">CVE-2007-3782</cve>
                <bugzilla href="http://bugzilla.redhat.com/194613" id="194613">CVE-2006-0903 Mysql log file obfuscation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/202246" id="202246">CVE-2006-4031 MySQL improper permission revocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/216427" id="216427">CVE-2006-4227 mysql improper suid argument evaluation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/232603" id="232603">CVE-2007-1420 Single MySQL worker can be crashed (NULL deref) with certain SELECT statements</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240813" id="240813">CVE-2007-2583 mysql: DoS via statement with crafted IF clause</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241688" id="241688">CVE-2007-2691 mysql DROP privilege not enforced when renaming tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241689" id="241689">CVE-2007-2692 mysql SECURITY INVOKER functions do not drop privileges</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248553" id="248553">CVE-2007-3781 CVE-2007-3782 New release of MySQL fixes security bugs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/254012" id="254012">Mysql bug 20048: 5.0.22 FLUSH TABLES WITH READ LOCK bug; need upgrade to 5.0.23</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/256501" id="256501">mysql 5.0.22 still has a lot of bugs ; need upgrade</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/349121" id="349121">MySQL client will display empty strings as NULL (fixed in 5.0.23)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434264" id="434264">CVE-2006-7232 mysql: daemon crash via EXPLAIN on queries on information schema</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435391" id="435391">mysql does not calculate thread stack size correctly for RHEL5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080364010" comment="mysql-test is earlier than 0:5.0.45-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080364011" comment="mysql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080364002" comment="mysql is earlier than 0:5.0.45-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080364003" comment="mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080364004" comment="mysql-server is earlier than 0:5.0.45-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080364005" comment="mysql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080364008" comment="mysql-bench is earlier than 0:5.0.45-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080364009" comment="mysql-bench is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080364006" comment="mysql-devel is earlier than 0:5.0.45-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080364007" comment="mysql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080389" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0389: nss_ldap security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0389-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0389.html" />
          <reference source="CVE" ref_id="CVE-2007-5794" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5794.html" />
    
    <description>The nss_ldap package contains the nss_ldap and pam_ldap modules. The
nss_ldap module is a plug-in which allows applications to retrieve
information about users and groups from a directory server. The pam_ldap
module allows PAM-aware applications to use a directory server to verify
user passwords.

A race condition was discovered in nss_ldap which affected certain
applications which make LDAP connections, such as Dovecot. This could cause
nss_ldap to answer a request for information about one user with
information about a different user. (CVE-2007-5794)

In addition, these updated packages fix the following bugs:

* a build error prevented the nss_ldap module from being able to use DNS to
discover the location of a directory server. For example, when the
/etc/nsswitch.conf configuration file was configured to use "ldap", but no
"host" or "uri" option was configured in the /etc/ldap.conf configuration
file, no directory server was contacted, and no results were returned.

* the "port" option in the /etc/ldap.conf configuration file on client
machines was ignored. For example, if a directory server which you were
attempting to use was listening on a non-default port (i.e. not ports 389
or 636), it was only possible to use that directory server by including the
port number in the "uri" option. In this updated package, the "port" option
works as expected.

* pam_ldap failed to change an expired password if it had to follow a
referral to do so, which could occur, for example, when using a slave
directory server in a replicated environment. An error such as the
following occurred after entering a new password: "LDAP password
information update failed: Can't contact LDAP server Insufficient 'write'
privilege to the 'userPassword' attribute"

This has been resolved in this updated package.

* when the "pam_password exop_send_old" password-change method was
configured in the /etc/ldap.conf configuration file, a logic error in the
pam_ldap module caused client machines to attempt to change a user's
password twice. First, the pam_ldap module attempted to change the password
using the "exop" request, and then again using an LDAP modify request.

* on Red Hat Enterprise Linux 5.1, rebuilding nss_ldap-253-5.el5 when the
krb5-*-1.6.1-17.el5 packages were installed failed due to an error such as
the following:

	+ /builddir/build/SOURCES/dlopen.sh ./nss_ldap-253/nss_ldap.so
	dlopen() of "././nss_ldap-253/nss_ldap.so" failed:
	./././nss_ldap-253/nss_ldap.so: undefined symbol: request_key
	error: Bad exit status from /var/tmp/rpm-tmp.62652 (%build)

The missing libraries have been added, which resolves this issue.

When recursively enumerating the set of members in a given group, the
module would allocate insufficient space for storing the set of member
names if the group itself contained other groups, thus corrupting the heap.
This update includes a backported fix for this bug.

Users of nss_ldap should upgrade to these updated packages, which contain
backported patches to correct this issue and fix these bugs.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5794.html">CVE-2007-5794</cve>
                <bugzilla href="http://bugzilla.redhat.com/254172" id="254172">Automatic DNS discovery of the LDAP server does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/364501" id="364501">pam_ldap tries to change passwords twice</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/367461" id="367461">CVE-2007-5794 nss_ldap randomly replying with wrong user's data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427370" id="427370">RHEL 5.1 nss_ldap does not build with RHEL 5.1 krb5 packages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080389002" comment="nss_ldap is earlier than 0:253-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080389003" comment="nss_ldap is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080485" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0485: compiz security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0485-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0485.html" />
          <reference source="CVE" ref_id="CVE-2007-3920" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-3920.html" />
    
    <description>Compiz is an OpenGL-based window and compositing manager.

Most screen savers create a top-level fullscreen window to cover the
desktop, and grab the input with that window. Compiz has an option to
un-redirect that window, but in some cases, this breaks the grab and
compromises the locked screen. (CVE-2007-3920)

Users of compiz are advised to upgrade to these updated packages, which
remove this option to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-3920.html">CVE-2007-3920</cve>
                <bugzilla href="http://bugzilla.redhat.com/350271" id="350271">CVE-2007-3920 gnome-screensaver loses keyboard grab when running under compiz</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080485002" comment="compiz is earlier than 0:0.0.13-0.37.20060817git.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080485003" comment="compiz is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080485004" comment="compiz-devel is earlier than 0:0.0.13-0.37.20060817git.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080485005" comment="compiz-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080486" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0486: nfs-utils security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0486-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0486.html" />
          <reference source="CVE" ref_id="CVE-2008-1376" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1376.html" />
    
    <description>The nfs-utils package provides a daemon for the kernel NFS server and
related tools.

A flaw was found in the nfs-utils package build. The nfs-utils package was
missing TCP wrappers support, which could result in an administrator
believing they had access restrictions enabled when they did not.
(CVE-2008-1376)

Users of nfs-utils are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-31" />
        <updated date="2008-07-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1376.html">CVE-2008-1376</cve>
                <bugzilla href="http://bugzilla.redhat.com/440114" id="440114">CVE-2008-1376 nfs-utils: missing tcp_wrappers support</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080486002" comment="nfs-utils is earlier than 1:1.0.9-35z.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080486003" comment="nfs-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080489" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0489: gnutls security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0489-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0489.html" />
          <reference source="CVE" ref_id="CVE-2008-1948" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1948.html" />
          <reference source="CVE" ref_id="CVE-2008-1949" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1949.html" />
          <reference source="CVE" ref_id="CVE-2008-1950" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1950.html" />
    
    <description>The GnuTLS Library provides support for cryptographic algorithms and
protocols such as TLS. GnuTLS includes libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Flaws were found in the way GnuTLS handles malicious client connections. A
malicious remote client could send a specially crafted request to a service
using GnuTLS that could cause the service to crash. (CVE-2008-1948,
CVE-2008-1949, CVE-2008-1950)

We believe it is possible to leverage the flaw CVE-2008-1948 to execute
arbitrary code but have been unable to prove this at the time of releasing
this advisory. Red Hat Enterprise Linux 5 includes applications, such as
CUPS, that would be directly vulnerable to any such an exploit, however.
Consequently, we have assigned it critical severity.

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1948.html">CVE-2008-1948</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1949.html">CVE-2008-1949</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1950.html">CVE-2008-1950</cve>
                <bugzilla href="http://bugzilla.redhat.com/447461" id="447461">CVE-2008-1948 GNUTLS-SA-2008-1-1 GnuTLS buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447462" id="447462">CVE-2008-1949 GNUTLS-SA-2008-1-2 GnuTLS null-pointer dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447463" id="447463">CVE-2008-1950 GNUTLS-SA-2008-1-3 GnuTLS memory overread flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080489006" comment="gnutls-utils is earlier than 0:1.4.1-3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080489007" comment="gnutls-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080489004" comment="gnutls-devel is earlier than 0:1.4.1-3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080489005" comment="gnutls-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080489002" comment="gnutls is earlier than 0:1.4.1-3.el5_1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080489003" comment="gnutls is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080492" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0492: gnutls security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0492-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0492.html" />
          <reference source="CVE" ref_id="CVE-2008-1948" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1948.html" />
          <reference source="CVE" ref_id="CVE-2008-1949" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1949.html" />
          <reference source="CVE" ref_id="CVE-2008-1950" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1950.html" />
    
    <description>The GnuTLS Library provides support for cryptographic algorithms and
protocols such as TLS. GnuTLS includes libtasn1, a library developed for
ASN.1 structures management that includes DER encoding and decoding.

Flaws were found in the way GnuTLS handles malicious client connections. A
malicious remote client could send a specially crafted request to a service
using GnuTLS that could cause the service to crash. (CVE-2008-1948,
CVE-2008-1949, CVE-2008-1950)

We believe it is possible to leverage the flaw CVE-2008-1948 to execute
arbitrary code but have been unable to prove this at the time of releasing
this advisory. Red Hat Enterprise Linux 4 does not ship with any
applications directly affected by this flaw. Third-party software which
runs on Red Hat Enterprise Linux 4 could, however, be affected by this
vulnerability. Consequently, we have assigned it important severity.

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-05-20" />
        <updated date="2008-05-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1948.html">CVE-2008-1948</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1949.html">CVE-2008-1949</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1950.html">CVE-2008-1950</cve>
                <bugzilla href="http://bugzilla.redhat.com/447461" id="447461">CVE-2008-1948 GNUTLS-SA-2008-1-1 GnuTLS buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447462" id="447462">CVE-2008-1949 GNUTLS-SA-2008-1-2 GnuTLS null-pointer dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447463" id="447463">CVE-2008-1950 GNUTLS-SA-2008-1-3 GnuTLS memory overread flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080492004" comment="gnutls-devel is earlier than 0:1.0.20-4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080492005" comment="gnutls-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080492002" comment="gnutls is earlier than 0:1.0.20-4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080492003" comment="gnutls is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080497" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0497: sblim security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0497-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0497.html" />
          <reference source="CVE" ref_id="CVE-2008-1951" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1951.html" />
    
    <description>SBLIM stands for Standards-Based Linux Instrumentation for Manageability.
It consists of a set of standards-based, Web-Based Enterprise Management
(WBEM) modules that use the Common Information Model (CIM) standard to
gather and provide systems management information, events, and methods to
local or networked consumers via a CIM object services broker using the
CMPI (Common Manageability Programming Interface) standard. This package
provides a set of core providers and development tools for systems
management applications.

It was discovered that certain sblim libraries had an RPATH (runtime
library search path) set in the ELF (Executable and Linking Format) header.
This RPATH pointed to a sub-directory of a world-writable, temporary
directory. A local user could create a file with the same name as a library
required by sblim (such as libc.so) and place it in the directory defined
in the RPATH. This file could then execute arbitrary code with the
privileges of the user running an application that used sblim (eg
tog-pegasus). (CVE-2008-1951)

Users are advised to upgrade to these updated sblim packages, which resolve
this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-24" />
        <updated date="2008-06-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1951.html">CVE-2008-1951</cve>
                <bugzilla href="http://bugzilla.redhat.com/447705" id="447705">CVE-2008-1951 sblim: libraries built with insecure RPATH</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497038" comment="sblim-cmpi-samba is earlier than 0:0.5.2-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497039" comment="sblim-cmpi-samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497032" comment="sblim-gather is earlier than 0:2.1.2-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497033" comment="sblim-gather is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497026" comment="sblim-cmpi-dns is earlier than 0:0.5.2-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497027" comment="sblim-cmpi-dns is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497050" comment="sblim-gather-provider is earlier than 0:2.1.2-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497051" comment="sblim-gather-provider is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497012" comment="sblim-wbemcli is earlier than 0:1.5.1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497013" comment="sblim-wbemcli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497076" comment="sblim-cmpi-dns-test is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497077" comment="sblim-cmpi-dns-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497060" comment="sblim-gather-test is earlier than 0:2.1.2-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497061" comment="sblim-gather-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497056" comment="sblim-cmpi-network-devel is earlier than 0:1.3.8-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497057" comment="sblim-cmpi-network-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497036" comment="sblim-cim-client-manual is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497037" comment="sblim-cim-client-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497034" comment="sblim-tools-libra is earlier than 0:0.2.3-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497035" comment="sblim-tools-libra is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497018" comment="sblim-gather-devel is earlier than 0:2.1.2-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497019" comment="sblim-gather-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497006" comment="sblim-cmpi-base is earlier than 0:1.5.5-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497007" comment="sblim-cmpi-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497070" comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.4-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497071" comment="sblim-cmpi-fsvol-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497046" comment="sblim-cmpi-network is earlier than 0:1.3.8-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497047" comment="sblim-cmpi-network is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497042" comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.4-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497043" comment="sblim-cmpi-fsvol-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497010" comment="sblim-cmpi-params-test is earlier than 0:1.2.6-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497011" comment="sblim-cmpi-params-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497002" comment="sblim is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497003" comment="sblim is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497062" comment="sblim-cim-client-javadoc is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497063" comment="sblim-cim-client-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497048" comment="sblim-cim-client is earlier than 0:1.3.3-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497049" comment="sblim-cim-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497028" comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.9-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497029" comment="sblim-cmpi-sysfs-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497072" comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.14-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497073" comment="sblim-cmpi-nfsv3 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497068" comment="sblim-testsuite is earlier than 0:1.2.4-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497069" comment="sblim-testsuite is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497064" comment="sblim-cmpi-devel is earlier than 0:1.0.4-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497065" comment="sblim-cmpi-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497058" comment="sblim-cmpi-base-devel is earlier than 0:1.5.5-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497059" comment="sblim-cmpi-base-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497052" comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.12-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497053" comment="sblim-cmpi-nfsv4-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497040" comment="sblim-cmpi-samba-devel is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497041" comment="sblim-cmpi-samba-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497030" comment="sblim-cmpi-network-test is earlier than 0:1.3.8-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497031" comment="sblim-cmpi-network-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497016" comment="sblim-cmpi-fsvol is earlier than 0:1.4.4-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497017" comment="sblim-cmpi-fsvol is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497014" comment="sblim-cmpi-params is earlier than 0:1.2.6-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497015" comment="sblim-cmpi-params is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497008" comment="sblim-cmpi-dns-devel is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497009" comment="sblim-cmpi-dns-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497066" comment="sblim-tools-libra-devel is earlier than 0:0.2.3-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497067" comment="sblim-tools-libra-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497044" comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.12-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497045" comment="sblim-cmpi-nfsv4 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497024" comment="sblim-cmpi-samba-test is earlier than 0:1-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497025" comment="sblim-cmpi-samba-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497022" comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.14-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497023" comment="sblim-cmpi-nfsv3-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497004" comment="sblim-cmpi-base-test is earlier than 0:1.5.5-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497005" comment="sblim-cmpi-base-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497074" comment="sblim-cmpi-syslog is earlier than 0:0.7.11-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497075" comment="sblim-cmpi-syslog is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497054" comment="sblim-cmpi-syslog-test is earlier than 0:0.7.11-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497055" comment="sblim-cmpi-syslog-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497020" comment="sblim-cmpi-sysfs is earlier than 0:1.1.9-31.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497021" comment="sblim-cmpi-sysfs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497097" comment="sblim-gather is earlier than 0:2.1.1-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497098" comment="sblim-gather is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497117" comment="sblim-gather-provider is earlier than 0:2.1.1-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497118" comment="sblim-gather-provider is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497087" comment="sblim-wbemcli is earlier than 0:1.5.1-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497088" comment="sblim-wbemcli is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497123" comment="sblim-cmpi-network-devel is earlier than 0:1.3.7-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497124" comment="sblim-cmpi-network-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497113" comment="sblim-gather-test is earlier than 0:2.1.1-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497114" comment="sblim-gather-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497091" comment="sblim-cmpi-base is earlier than 0:1.5.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497092" comment="sblim-cmpi-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497081" comment="sblim-gather-devel is earlier than 0:2.1.1-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497082" comment="sblim-gather-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497107" comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.3-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497108" comment="sblim-cmpi-fsvol-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497105" comment="sblim-cmpi-network is earlier than 0:1.3.7-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497106" comment="sblim-cmpi-network is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497101" comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.3-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497102" comment="sblim-cmpi-fsvol-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497083" comment="sblim-cmpi-params-test is earlier than 0:1.2.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497084" comment="sblim-cmpi-params-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497079" comment="sblim is earlier than 0:1-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497080" comment="sblim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497095" comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.8-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497096" comment="sblim-cmpi-sysfs-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497131" comment="sblim-cmpi-devel is earlier than 0:1.0.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497132" comment="sblim-cmpi-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497125" comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.11-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497126" comment="sblim-cmpi-nfsv4-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497121" comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.13-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497122" comment="sblim-cmpi-nfsv3 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497119" comment="sblim-cmpi-base-devel is earlier than 0:1.5.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497120" comment="sblim-cmpi-base-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497115" comment="sblim-cmpi-fsvol is earlier than 0:1.4.3-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497116" comment="sblim-cmpi-fsvol is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497111" comment="sblim-cmpi-network-test is earlier than 0:1.3.7-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497112" comment="sblim-cmpi-network-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497109" comment="sblim-cmpi-params is earlier than 0:1.2.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497110" comment="sblim-cmpi-params is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497085" comment="sblim-testsuite is earlier than 0:1.2.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497086" comment="sblim-testsuite is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497129" comment="sblim-cmpi-base-test is earlier than 0:1.5.4-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497130" comment="sblim-cmpi-base-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497127" comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.13-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497128" comment="sblim-cmpi-nfsv3-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497099" comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.11-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497100" comment="sblim-cmpi-nfsv4 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497103" comment="sblim-cmpi-syslog is earlier than 0:0.7.9-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497104" comment="sblim-cmpi-syslog is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497093" comment="sblim-cmpi-syslog-test is earlier than 0:0.7.9-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497094" comment="sblim-cmpi-syslog-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080497089" comment="sblim-cmpi-sysfs is earlier than 0:1.1.8-13a.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080497090" comment="sblim-cmpi-sysfs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080498" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0498: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0498-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0498.html" />
          <reference source="CVE" ref_id="CVE-2008-1722" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1722.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An integer overflow flaw leading to a heap buffer overflow was discovered
in the Portable Network Graphics (PNG) decoding routines used by the CUPS
image converting filters "imagetops" and "imagetoraster". An attacker could
create a malicious PNG file that could possibly execute arbitrary code as
the "lp" user if the file was printed. (CVE-2008-1722)

All CUPS users are advised to upgrade to these updated packages, which
contain backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-04" />
        <updated date="2008-06-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1722.html">CVE-2008-1722</cve>
                <bugzilla href="http://bugzilla.redhat.com/441692" id="441692">CVE-2008-1722 cups: integer overflow in the image filter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498006" comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498008" comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498004" comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498002" comment="cups is earlier than 1:1.2.4-11.18.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498015" comment="cups-devel is earlier than 1:1.1.17-13.3.53" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498013" comment="cups-libs is earlier than 1:1.1.17-13.3.53" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498011" comment="cups is earlier than 1:1.1.17-13.3.53" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498020" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498019" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080498018" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080502" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0502: XFree86 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0502-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0502.html" />
          <reference source="CVE" ref_id="CVE-2008-1377" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1377.html" />
          <reference source="CVE" ref_id="CVE-2008-1379" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1379.html" />
          <reference source="CVE" ref_id="CVE-2008-2360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2360.html" />
          <reference source="CVE" ref_id="CVE-2008-2361" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2361.html" />
    
    <description>XFree86 is an implementation of the X Window System, which provides the
core functionality for the Linux graphical desktop.

An input validation flaw was discovered in X.org's Security and Record
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or, potentially, execute arbitrary code with
root privileges on the X.Org server. (CVE-2008-1377)

Multiple integer overflow flaws were found in X.org's Render extension. A
malicious authorized client could exploit these issues to cause a denial of
service (crash) or, potentially, execute arbitrary code with root
privileges on the X.Org server. (CVE-2008-2360, CVE-2008-2361)

An input validation flaw was discovered in X.org's MIT-SHM extension. A
client connected to the X.org server could read arbitrary server memory.
This could result in the sensitive data of other users of the X.org server
being disclosed. (CVE-2008-1379)

Users of XFree86 are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-11" />
        <updated date="2008-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1377.html">CVE-2008-1377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1379.html">CVE-2008-1379</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2360.html">CVE-2008-2360</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2361.html">CVE-2008-2361</cve>
                <bugzilla href="http://bugzilla.redhat.com/445403" id="445403">CVE-2008-1377 X.org Record and Security extensions memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445414" id="445414">CVE-2008-1379 X.org MIT-SHM extension arbitrary memory read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448783" id="448783">CVE-2008-2360 X.org Render extension AllocateGlyph() heap buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448784" id="448784">CVE-2008-2361 X.org Render extension ProcRenderCreateCursor() crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502058" comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029023" comment="XFree86-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502030" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029053" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502048" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029007" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502044" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029009" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502034" comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029025" comment="XFree86-libs-data is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502040" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029039" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502018" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029035" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502006" comment="XFree86-doc is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029043" comment="XFree86-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502002" comment="XFree86 is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029003" comment="XFree86 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502028" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029057" comment="XFree86-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502026" comment="XFree86-libs is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029061" comment="XFree86-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502024" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029047" comment="XFree86-truetype-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502032" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029033" comment="XFree86-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502010" comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029019" comment="XFree86-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502004" comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029011" comment="XFree86-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502056" comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029015" comment="XFree86-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502036" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029029" comment="XFree86-syriac-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502016" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029037" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502050" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029051" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502042" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029005" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502022" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029055" comment="XFree86-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502014" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029045" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502052" comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029049" comment="XFree86-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502046" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029059" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502020" comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029031" comment="XFree86-base-fonts is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502060" comment="XFree86-tools is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029017" comment="XFree86-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502054" comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029041" comment="XFree86-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502038" comment="XFree86-twm is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029027" comment="XFree86-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502012" comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029021" comment="XFree86-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080502008" comment="XFree86-devel is earlier than 0:4.3.0-128.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080029013" comment="XFree86-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080503" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0503: xorg-x11 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0503-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0503.html" />
          <reference source="CVE" ref_id="CVE-2008-1377" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1377.html" />
          <reference source="CVE" ref_id="CVE-2008-1379" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1379.html" />
          <reference source="CVE" ref_id="CVE-2008-2360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2360.html" />
          <reference source="CVE" ref_id="CVE-2008-2361" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2361.html" />
    
    <description>The xorg-x11 packages contain X.Org, an open source implementation of the X
Window System. It provides the basic low-level functionality that
full-fledged graphical user interfaces are designed upon.

An input validation flaw was discovered in X.org's Security and Record
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or, potentially, execute arbitrary code with
root privileges on the X.Org server. (CVE-2008-1377)

Multiple integer overflow flaws were found in X.org's Render extension. A
malicious authorized client could exploit these issues to cause a denial of
service (crash) or, potentially, execute arbitrary code with root
privileges on the X.Org server. (CVE-2008-2360, CVE-2008-2361)

An input validation flaw was discovered in X.org's MIT-SHM extension. A
client connected to the X.org server could read arbitrary server memory.
This could result in the sensitive data of other users of the X.org server
being disclosed. (CVE-2008-1379)

Users of xorg-x11 should upgrade to these updated packages, which contain
backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-11" />
        <updated date="2008-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1377.html">CVE-2008-1377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1379.html">CVE-2008-1379</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2360.html">CVE-2008-2360</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2361.html">CVE-2008-2361</cve>
                <bugzilla href="http://bugzilla.redhat.com/445403" id="445403">CVE-2008-1377 X.org Record and Security extensions memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445414" id="445414">CVE-2008-1379 X.org MIT-SHM extension arbitrary memory read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448783" id="448783">CVE-2008-2360 X.org Render extension AllocateGlyph() heap buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448784" id="448784">CVE-2008-2361 X.org Render extension ProcRenderCreateCursor() crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503030" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030037" comment="xorg-x11-xdm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503022" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030011" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503008" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030005" comment="xorg-x11-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503020" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030017" comment="xorg-x11-xfs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503018" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030015" comment="xorg-x11-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503010" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030021" comment="xorg-x11-Xnest is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503006" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030029" comment="xorg-x11-sdk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503002" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030003" comment="xorg-x11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503034" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030027" comment="xorg-x11-Xdmx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503016" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030035" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503004" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030009" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503032" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030007" comment="xorg-x11-Xvfb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503028" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030019" comment="xorg-x11-twm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503014" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030033" comment="xorg-x11-font-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503012" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030025" comment="xorg-x11-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503036" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030031" comment="xorg-x11-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503026" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030013" comment="xorg-x11-xauth is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080503024" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080030023" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080504" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0504: xorg-x11-server security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0504-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0504.html" />
          <reference source="CVE" ref_id="CVE-2008-1377" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1377.html" />
          <reference source="CVE" ref_id="CVE-2008-1379" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1379.html" />
          <reference source="CVE" ref_id="CVE-2008-2360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2360.html" />
          <reference source="CVE" ref_id="CVE-2008-2361" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2361.html" />
          <reference source="CVE" ref_id="CVE-2008-2362" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2362.html" />
    
    <description>X.Org is an open source implementation of the X Window System. It provides
basic low-level functionality that full-fledged graphical user interfaces
are designed upon.

An input validation flaw was discovered in X.org's Security and Record
extensions. A malicious authorized client could exploit this issue to cause
a denial of service (crash) or, potentially, execute arbitrary code with
root privileges on the X.Org server. (CVE-2008-1377)

Multiple integer overflow flaws were found in X.org's Render extension. A
malicious authorized client could exploit these issues to cause a denial of
service (crash) or, potentially, execute arbitrary code with root
privileges on the X.Org server. (CVE-2008-2360, CVE-2008-2361,
CVE-2008-2362)

An input validation flaw was discovered in X.org's MIT-SHM extension. A
client connected to the X.org server could read arbitrary server memory.
This could result in the sensitive data of other users of the X.org server
being disclosed. (CVE-2008-1379)

Users of xorg-x11-server should upgrade to these updated packages, which
contain backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-11" />
        <updated date="2008-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1377.html">CVE-2008-1377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1379.html">CVE-2008-1379</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2360.html">CVE-2008-2360</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2361.html">CVE-2008-2361</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2362.html">CVE-2008-2362</cve>
                <bugzilla href="http://bugzilla.redhat.com/445403" id="445403">CVE-2008-1377 X.org Record and Security extensions memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445414" id="445414">CVE-2008-1379 X.org MIT-SHM extension arbitrary memory read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448783" id="448783">CVE-2008-2360 X.org Render extension AllocateGlyph() heap buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448784" id="448784">CVE-2008-2361 X.org Render extension ProcRenderCreateCursor() crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448785" id="448785">CVE-2008-2362 X.org Render extension input validation flaw causing memory corruption</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504016" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031005" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504014" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031011" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504006" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031015" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504012" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031009" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504004" comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080504005" comment="xorg-x11-server-randr-source is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504010" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031013" comment="xorg-x11-server-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504002" comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031003" comment="xorg-x11-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080504008" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080031007" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080508" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0508: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0508-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0508.html" />
          <reference source="CVE" ref_id="CVE-2008-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0598.html" />
          <reference source="CVE" ref_id="CVE-2008-1367" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1367.html" />
          <reference source="CVE" ref_id="CVE-2008-2365" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2365.html" />
          <reference source="CVE" ref_id="CVE-2008-2729" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2729.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* A security flaw was found in the Linux kernel memory copy routines, when
running on certain AMD64 systems. If an unsuccessful attempt to copy kernel
memory from source to destination memory locations occurred, the copy
routines did not zero the content at the destination memory location. This
could allow a local unprivileged user to view potentially sensitive data.
(CVE-2008-2729, Important)

* Alexey Dobriyan discovered a race condition in the Linux kernel
process-tracing system call, ptrace. A local unprivileged user could
use this flaw to cause a denial of service (kernel hang).
(CVE-2008-2365, Important)

* Tavis Ormandy discovered a deficiency in the Linux kernel 32-bit and
64-bit emulation. This could allow a local unprivileged user to prepare and
run a specially crafted binary, which would use this deficiency to leak
uninitialized and potentially sensitive data. (CVE-2008-0598, Important)

* It was discovered that the Linux kernel handled string operations in the
opposite way to the GNU Compiler Collection (GCC). This could allow a local
unprivileged user to cause memory corruption. (CVE-2008-1367, Low)

As well, these updated packages fix the following bug:

* On systems with a large number of CPUs (more than 16), multiple
applications calling the "times()" system call may have caused a system
hang.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-25" />
        <updated date="2008-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0598.html">CVE-2008-0598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1367.html">CVE-2008-1367</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2365.html">CVE-2008-2365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2729.html">CVE-2008-2729</cve>
                <bugzilla href="http://bugzilla.redhat.com/433938" id="433938">CVE-2008-0598 kernel: linux x86_64 ia32 emulation leaks uninitialized data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437312" id="437312">CVE-2008-1367 Kernel doesn't clear DF for signal handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449101" id="449101">[4.7] System goes unresponsive if times() syscall is called concurrently on many cpus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449359" id="449359">CVE-2008-2365 kernel: ptrace: Crash on PTRACE_{ATTACH,DETACH} race</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451271" id="451271">CVE-2008-2729 kernel: [x86_64]  The string instruction version didn't zero the output on exception.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508002" comment="kernel is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508022" comment="kernel-doc is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508004" comment="kernel-devel is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508010" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508020" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508006" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508016" comment="kernel-xenU is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508014" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080508012" comment="kernel-smp is earlier than 0:2.6.9-67.0.20.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080514" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0514: evolution security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0514-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0514.html" />
          <reference source="CVE" ref_id="CVE-2008-1108" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1108.html" />
          <reference source="CVE" ref_id="CVE-2008-1109" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1109.html" />
    
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution parsed iCalendar timezone attachment
data. If the Itip Formatter plug-in was disabled and a user opened a mail
with a carefully crafted iCalendar attachment, arbitrary code could be
executed as the user running Evolution. (CVE-2008-1108)

Note: the Itip Formatter plug-in, which allows calendar information
(attachments with a MIME type of "text/calendar") to be displayed as part
of the e-mail message, is enabled by default.

A heap-based buffer overflow flaw was found in the way Evolution parsed
iCalendar attachments with an overly long "DESCRIPTION" property string. If
a user responded to a carefully crafted iCalendar attachment in a
particular way, arbitrary code could be executed as the user running
Evolution. (CVE-2008-1109).

The particular response required to trigger this vulnerability was as
follows:

1. Receive the carefully crafted iCalendar attachment.
2. Accept the associated meeting.
3. Open the calender the meeting was in.
4. Reply to the sender.

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing these issues.

All Evolution users should upgrade to these updated packages, which contain
backported patches which resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-04" />
        <updated date="2008-06-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1108.html">CVE-2008-1108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1109.html">CVE-2008-1109</cve>
                <bugzilla href="http://bugzilla.redhat.com/448540" id="448540">CVE-2008-1108 evolution: iCalendar buffer overflow via large timezone specification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448541" id="448541">CVE-2008-1109 evolution: iCalendar buffer overflow via large description parameter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080514006" comment="evolution-help is earlier than 0:2.12.3-8.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080514007" comment="evolution-help is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080514002" comment="evolution is earlier than 0:2.12.3-8.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177003" comment="evolution is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080514004" comment="evolution-devel is earlier than 0:2.12.3-8.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177005" comment="evolution-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080515" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0515: evolution28 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0515-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0515.html" />
          <reference source="CVE" ref_id="CVE-2008-1108" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1108.html" />
          <reference source="CVE" ref_id="CVE-2008-1109" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1109.html" />
    
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution parsed iCalendar timezone attachment
data. If the Itip Formatter plug-in was disabled and a user opened a mail
with a carefully crafted iCalendar attachment, arbitrary code could be
executed as the user running Evolution. (CVE-2008-1108)

Note: the Itip Formatter plug-in, which allows calendar information
(attachments with a MIME type of "text/calendar") to be displayed as part
of the e-mail message, is enabled by default.

A heap-based buffer overflow flaw was found in the way Evolution parsed
iCalendar attachments with an overly long "DESCRIPTION" property string. If
a user responded to a carefully crafted iCalendar attachment in a
particular way, arbitrary code could be executed as the user running
Evolution. (CVE-2008-1109).

The particular response required to trigger this vulnerability was as
follows:

1. Receive the carefully crafted iCalendar attachment.
2. Accept the associated meeting.
3. Open the calender the meeting was in.
4. Reply to the sender.

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing these issues.

All Evolution users should upgrade to these updated packages, which contain
backported patches which resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-04" />
        <updated date="2008-06-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1108.html">CVE-2008-1108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1109.html">CVE-2008-1109</cve>
                <bugzilla href="http://bugzilla.redhat.com/448540" id="448540">CVE-2008-1108 evolution: iCalendar buffer overflow via large timezone specification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448541" id="448541">CVE-2008-1109 evolution: iCalendar buffer overflow via large description parameter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080515002" comment="evolution28 is earlier than 0:2.8.0-53.el4_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177012" comment="evolution28 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080515004" comment="evolution28-devel is earlier than 0:2.8.0-53.el4_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177014" comment="evolution28-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080516" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0516: evolution security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0516-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0516.html" />
          <reference source="CVE" ref_id="CVE-2008-1108" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1108.html" />
    
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications and personal information management (PIM) tools
for the GNOME desktop environment.

A flaw was found in the way Evolution parsed iCalendar timezone attachment
data. If mail which included a carefully crafted iCalendar attachment was
opened, arbitrary code could be executed as the user running Evolution.
(CVE-2008-1108)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly disclosing this issue.

All users of Evolution should upgrade to these updated packages, which
contains a backported patch which resolves this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-04" />
        <updated date="2008-06-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1108.html">CVE-2008-1108</cve>
                <bugzilla href="http://bugzilla.redhat.com/448540" id="448540">CVE-2008-1108 evolution: iCalendar buffer overflow via large timezone specification</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080516002" comment="evolution is earlier than 0:1.4.5-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177008" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080516004" comment="evolution-devel is earlier than 0:1.4.5-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177010" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080516007" comment="evolution is earlier than 0:2.0.2-35.0.4.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177008" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080516008" comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4_6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080177010" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080519" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0519: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0519-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0519.html" />
          <reference source="CVE" ref_id="CVE-2008-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0598.html" />
          <reference source="CVE" ref_id="CVE-2008-2358" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2358.html" />
          <reference source="CVE" ref_id="CVE-2008-2729" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2729.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* A security flaw was found in the Linux kernel memory copy routines, when
running on certain AMD64 systems. If an unsuccessful attempt to copy kernel
memory from source to destination memory locations occurred, the copy
routines did not zero the content at the destination memory location. This
could allow a local unprivileged user to view potentially sensitive data.
(CVE-2008-2729, Important)

* Tavis Ormandy discovered a deficiency in the Linux kernel 32-bit and
64-bit emulation. This could allow a local unprivileged user to prepare and
run a specially crafted binary, which would use this deficiency to leak
uninitialized and potentially sensitive data. (CVE-2008-0598, Important)

* Brandon Edwards discovered a missing length validation check in the Linux
kernel DCCP module reconciliation feature. This could allow a local
unprivileged user to cause a heap overflow, gaining privileges for
arbitrary code execution. (CVE-2008-2358, Moderate)

As well, these updated packages fix the following bug:

* Due to a regression, "gettimeofday" may have gone backwards on certain
x86 hardware. This issue was quite dangerous for time-sensitive systems,
such as those used for transaction systems and databases, and may have
caused applications to produce incorrect results, or even crash.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-25" />
        <updated date="2008-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0598.html">CVE-2008-0598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2358.html">CVE-2008-2358</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2729.html">CVE-2008-2729</cve>
                <bugzilla href="http://bugzilla.redhat.com/433938" id="433938">CVE-2008-0598 kernel: linux x86_64 ia32 emulation leaks uninitialized data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447389" id="447389">CVE-2008-2358 kernel: dccp: sanity check feature length</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451271" id="451271">CVE-2008-2729 kernel: [x86_64]  The string instruction version didn't zero the output on exception.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519004" comment="kernel-headers is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519002" comment="kernel is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519024" comment="kernel-doc is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519022" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519014" comment="kernel-devel is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519010" comment="kernel-debug is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519018" comment="kernel-kdump is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519008" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519006" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519020" comment="kernel-PAE is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519016" comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080519012" comment="kernel-xen is earlier than 0:2.6.18-92.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080522" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0522: perl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0522-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0522.html" />
          <reference source="CVE" ref_id="CVE-2008-1927" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1927.html" />
    
    <description>Perl is a high-level programming language commonly used for system
administration utilities and Web programming.

A flaw was found in Perl's regular expression engine. A specially crafted
regular expression with Unicode characters could trigger a buffer overflow,
causing Perl to crash, or possibly execute arbitrary code with the
privileges of the user running Perl. (CVE-2008-1927)

Users of perl are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-11" />
        <updated date="2008-06-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1927.html">CVE-2008-1927</cve>
                <bugzilla href="http://bugzilla.redhat.com/443928" id="443928">CVE-2008-1927 perl: heap corruption by regular expressions with utf8 characters</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522004" comment="perl-suidperl is earlier than 4:5.8.8-10.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522005" comment="perl-suidperl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522002" comment="perl is earlier than 4:5.8.8-10.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522003" comment="perl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522013" comment="perl-CGI is earlier than 2:2.89-98.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522014" comment="perl-CGI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522015" comment="perl-DB_File is earlier than 2:1.806-98.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522016" comment="perl-DB_File is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522009" comment="perl-suidperl is earlier than 2:5.8.0-98.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522010" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522011" comment="perl-CPAN is earlier than 2:1.61-98.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522012" comment="perl-CPAN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522007" comment="perl is earlier than 2:5.8.0-98.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522008" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522019" comment="perl-suidperl is earlier than 3:5.8.5-36.el4_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522010" comment="perl-suidperl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080522018" comment="perl is earlier than 3:5.8.5-36.el4_6.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080522008" comment="perl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080529" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0529: net-snmp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0529-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0529.html" />
          <reference source="CVE" ref_id="CVE-2008-2292" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2292.html" />
          <reference source="CVE" ref_id="CVE-2008-0960" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0960.html" />
    
    <description>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

A flaw was found in the way Net-SNMP checked an SNMPv3 packet's Keyed-Hash
Message Authentication Code (HMAC). An attacker could use this flaw to
spoof an authenticated SNMPv3 packet. (CVE-2008-0960)

A buffer overflow was found in the Perl bindings for Net-SNMP. This could
be exploited if an attacker could convince an application using the
Net-SNMP Perl module to connect to a malicious SNMP agent. (CVE-2008-2292)

All users of net-snmp should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-10" />
        <updated date="2008-06-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2292.html">CVE-2008-2292</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0960.html">CVE-2008-0960</cve>
                <bugzilla href="http://bugzilla.redhat.com/447262" id="447262">CVE-2008-2292 net-snmp: buffer overflow in perl module's Perl Module __snprint_value()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447974" id="447974">CVE-2008-0960 net-snmp SNMPv3 authentication bypass (VU#877044)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529006" comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529007" comment="net-snmp-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529010" comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529011" comment="net-snmp-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529008" comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529009" comment="net-snmp-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529004" comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529005" comment="net-snmp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529002" comment="net-snmp is earlier than 1:5.3.1-24.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529003" comment="net-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529017" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529018" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529019" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529020" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529021" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529022" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529015" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529016" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529013" comment="net-snmp is earlier than 0:5.0.9-2.30E.24" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529014" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529028" comment="net-snmp-utils is earlier than 0:5.1.2-11.el4_6.11.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529018" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529025" comment="net-snmp-libs is earlier than 0:5.1.2-11.el4_6.11.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529020" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529027" comment="net-snmp-devel is earlier than 0:5.1.2-11.el4_6.11.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529016" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529026" comment="net-snmp-perl is earlier than 0:5.1.2-11.el4_6.11.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529022" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080529024" comment="net-snmp is earlier than 0:5.1.2-11.el4_6.11.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529014" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080533" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0533: bind security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0533-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0533.html" />
          <reference source="CVE" ref_id="CVE-2008-1447" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1447.html" />
    
    <description>ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.

The DNS protocol protects against spoofing attacks by requiring an attacker
to predict both the DNS transaction ID and UDP source port of a request. In
recent years, a number of papers have found problems with DNS
implementations which make it easier for an attacker to perform DNS
cache-poisoning attacks.

Previous versions of BIND did not use randomized UDP source ports. If an
attacker was able to predict the random DNS transaction ID, this could make
DNS cache-poisoning attacks easier. In order to provide more resilience,
BIND has been updated to use a range of random UDP source ports.
(CVE-2008-1447)

Note: This errata also updates SELinux policy on Red Hat Enterprise Linux 4
and 5 to allow BIND to use random UDP source ports.

Users of BIND are advised to upgrade to these updated packages, which
contain a backported patch to add this functionality.

Red Hat would like to thank Dan Kaminsky for reporting this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-08" />
        <updated date="2008-07-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1447.html">CVE-2008-1447</cve>
                <bugzilla href="http://bugzilla.redhat.com/449345" id="449345">CVE-2008-1447 implement source UDP port randomization (CERT VU#800113)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454852" id="454852">Default caching-nameserver configuration blocks fixes for CVE-2008-1447 (rhel-5)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533004" comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533005" comment="selinux-policy-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533008" comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533009" comment="selinux-policy-mls is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533006" comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533007" comment="selinux-policy-targeted is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533010" comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533011" comment="selinux-policy-strict is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533002" comment="selinux-policy is earlier than 0:2.4.6-137.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533003" comment="selinux-policy is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533026" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300007" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533022" comment="bind-utils is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300017" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533020" comment="bind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300005" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533018" comment="bind-chroot is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300015" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533024" comment="bind-sdb is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300009" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533012" comment="bind is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533016" comment="bind-libs is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300011" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533014" comment="caching-nameserver is earlier than 30:9.3.4-6.0.2.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080300013" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533037" comment="bind-chroot is earlier than 20:9.2.4-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533038" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533035" comment="bind-utils is earlier than 20:9.2.4-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533036" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533031" comment="bind-devel is earlier than 20:9.2.4-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533032" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533029" comment="bind is earlier than 20:9.2.4-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533030" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533033" comment="bind-libs is earlier than 20:9.2.4-22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533034" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533043" comment="bind-utils is earlier than 20:9.2.4-28.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533036" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533042" comment="bind-devel is earlier than 20:9.2.4-28.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533032" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533041" comment="bind-chroot is earlier than 20:9.2.4-28.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533038" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533040" comment="bind is earlier than 20:9.2.4-28.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533030" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533044" comment="bind-libs is earlier than 20:9.2.4-28.0.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533034" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533047" comment="selinux-policy-targeted-sources is earlier than 0:1.17.30-2.150.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533048" comment="selinux-policy-targeted-sources is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080533045" comment="selinux-policy-targeted is earlier than 0:1.17.30-2.150.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080533046" comment="selinux-policy-targeted is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080537" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0537: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0537-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0537.html" />
          <reference source="CVE" ref_id="CVE-2008-2152" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2152.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Sean Larsson found a heap overflow flaw in the OpenOffice memory allocator.
If a carefully crafted file was opened by a victim, an attacker could use
the flaw to crash OpenOffice.org or, possibly, execute arbitrary code.
(CVE-2008-2152)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain a backported fix to correct this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-12" />
        <updated date="2008-06-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2152.html">CVE-2008-2152</cve>
                <bugzilla href="http://bugzilla.redhat.com/450518" id="450518">CVE-2008-2152 OpenOffice.org overflow possible on allocation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537002" comment="openoffice.org is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537034" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175073" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537074" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175149" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537088" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175079" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537138" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175047" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537064" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175119" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537066" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175089" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537086" comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175125" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537124" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175031" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537068" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175101" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537080" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175095" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537150" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175107" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537030" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175043" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537106" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175017" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537024" comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537025" comment="openoffice.org-headless is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537152" comment="openoffice.org-base is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175051" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537082" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175097" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537016" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175077" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537110" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175103" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537114" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175131" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537100" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175009" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537014" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175067" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537096" comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175135" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537018" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175133" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537094" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175147" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537130" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175029" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537046" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175109" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537004" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175115" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537050" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175049" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537084" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175081" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537052" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175023" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537060" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175037" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537104" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175025" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537118" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175105" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537122" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175111" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537032" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175007" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537092" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175145" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537140" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175063" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537026" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175011" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537136" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175035" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537036" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175075" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537076" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175015" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537048" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175013" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537148" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175069" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537040" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175127" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537054" comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175113" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537154" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537155" comment="openoffice.org-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537134" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175137" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537010" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175039" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537070" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175027" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537044" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175129" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537028" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175143" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537072" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175093" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537022" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175123" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537006" comment="openoffice.org-math is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175045" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537102" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175057" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537126" comment="openoffice.org-core is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175085" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537098" comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175141" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537132" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537108" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175099" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537058" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175121" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537020" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175021" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537090" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175091" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537008" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175071" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537042" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175117" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537120" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537121" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537062" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175055" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537142" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175061" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537056" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175139" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537116" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175065" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537078" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175005" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537112" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175041" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537146" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175053" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537144" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175019" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537038" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175059" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537012" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175087" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537128" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175083" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537255" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175258" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537253" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175244" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537251" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175214" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537235" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175176" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537233" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175266" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537229" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175228" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537225" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175262" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537173" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175184" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537269" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175252" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537223" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175186" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537201" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175218" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537193" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175208" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537169" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175226" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537241" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175192" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537209" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175194" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537161" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175230" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537265" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175220" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537183" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175242" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537181" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175160" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537165" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175206" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537157" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175152" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537261" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175250" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537249" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175178" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537245" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175256" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537227" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175212" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537211" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175154" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537203" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175240" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537195" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175182" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537191" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175164" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537185" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175216" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537177" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175174" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537175" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175248" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537171" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175158" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537267" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175234" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537259" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175264" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537213" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175210" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537197" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175162" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537163" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175224" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537263" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175246" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537215" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175156" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537207" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175170" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537199" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175190" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537189" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175202" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537187" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175236" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537179" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175260" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537159" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175254" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537273" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175222" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537271" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175232" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537239" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175172" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537221" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175168" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537257" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175268" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537247" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175188" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537243" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175180" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537231" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175196" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537219" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175238" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537217" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175198" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537205" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175200" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537167" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175166" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080537237" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.5.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175204" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080538" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0538: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0538-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0538.html" />
          <reference source="CVE" ref_id="CVE-2008-2152" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2152.html" />
          <reference source="CVE" ref_id="CVE-2008-2366" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2366.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

Sean Larsson found a heap overflow flaw in the OpenOffice memory allocator.
If a carefully crafted file was opened by a victim, an attacker could use
the flaw to crash OpenOffice.org or, possibly, execute arbitrary code.
(CVE-2008-2152)

It was discovered that certain libraries in the Red Hat Enterprise Linux 3
and 4 openoffice.org packages had an insecure relative RPATH (runtime
library search path) set in the ELF (Executable and Linking Format) header.
A local user able to convince another user to run OpenOffice in an
attacker-controlled directory, could run arbitrary code with the privileges
of the victim. (CVE-2008-2366)

All users of openoffice.org are advised to upgrade to these updated
packages, which contain backported fixes which correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-12" />
        <updated date="2008-06-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2152.html">CVE-2008-2152</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2366.html">CVE-2008-2366</cve>
                <bugzilla href="http://bugzilla.redhat.com/450518" id="450518">CVE-2008-2152 OpenOffice.org overflow possible on allocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450532" id="450532">CVE-2008-2366 openoffice.org: insecure relative RPATH in OOo 1.1.x packages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538004" comment="openoffice.org-i18n is earlier than 0:1.1.2-42.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538002" comment="openoffice.org is earlier than 0:1.1.2-42.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538006" comment="openoffice.org-libs is earlier than 0:1.1.2-42.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538011" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.5.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538009" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.5.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538012" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.5.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080538010" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.5.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080544" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0544: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0544-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0544.html" />
          <reference source="CVE" ref_id="CVE-2008-2051" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2051.html" />
          <reference source="CVE" ref_id="CVE-2007-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5898.html" />
          <reference source="CVE" ref_id="CVE-2007-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5899.html" />
          <reference source="CVE" ref_id="CVE-2007-4782" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4782.html" />
          <reference source="CVE" ref_id="CVE-2008-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2107.html" />
          <reference source="CVE" ref_id="CVE-2008-2108" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2108.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

It was discovered that the PHP escapeshellcmd() function did not properly
escape multi-byte characters which are not valid in the locale used by the
script. This could allow an attacker to bypass quoting restrictions imposed
by escapeshellcmd() and execute arbitrary commands if the PHP script was
using certain locales. Scripts using the default UTF-8 locale are not
affected by this issue. (CVE-2008-2051)

PHP functions htmlentities() and htmlspecialchars() did not properly
recognize partial multi-byte sequences. Certain sequences of bytes could be
passed through these functions without being correctly HTML-escaped.
Depending on the browser being used, an attacker could use this flaw to
conduct cross-site scripting attacks. (CVE-2007-5898)

A PHP script which used the transparent session ID configuration option, or
which used the output_add_rewrite_var() function, could leak session
identifiers to external web sites. If a page included an HTML form with an
ACTION attribute referencing a non-local URL, the user's session ID would
be included in the form data passed to that URL. (CVE-2007-5899)

It was discovered that PHP fnmatch() function did not restrict the length
of the string argument. An attacker could use this flaw to crash the PHP
interpreter where a script used fnmatch() on untrusted input data.
(CVE-2007-4782)

It was discovered that PHP did not properly seed its pseudo-random number
generator used by functions such as rand() and mt_rand(), possibly allowing
an attacker to easily predict the generated pseudo-random values.
(CVE-2008-2107, CVE-2008-2108)

Users of PHP should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-16" />
        <updated date="2008-07-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2051.html">CVE-2008-2051</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5898.html">CVE-2007-5898</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5899.html">CVE-2007-5899</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4782.html">CVE-2007-4782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2107.html">CVE-2008-2107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2108.html">CVE-2008-2108</cve>
                <bugzilla href="http://bugzilla.redhat.com/285881" id="285881">CVE-2007-4782 php crash in glob() and fnmatch() functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382411" id="382411">CVE-2007-5898 php htmlentities/htmlspecialchars multibyte sequences</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382431" id="382431">CVE-2007-5899 php session ID leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445006" id="445006">CVE-2008-2051 PHP multibyte shell escape flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445684" id="445684">CVE-2008-2107 PHP 32 bit weak random seed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445685" id="445685">CVE-2008-2108 PHP weak 64 bit random seed</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544024" comment="php-gd is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544025" comment="php-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544012" comment="php-soap is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544013" comment="php-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544010" comment="php-common is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544011" comment="php-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544008" comment="php-odbc is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544009" comment="php-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544022" comment="php-mysql is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544023" comment="php-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544002" comment="php is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544003" comment="php is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544026" comment="php-xmlrpc is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544027" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544030" comment="php-cli is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544031" comment="php-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544032" comment="php-mbstring is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544033" comment="php-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544028" comment="php-pgsql is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544029" comment="php-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544016" comment="php-xml is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544017" comment="php-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544034" comment="php-dba is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544035" comment="php-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544018" comment="php-devel is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544019" comment="php-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544038" comment="php-ncurses is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544039" comment="php-ncurses is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544020" comment="php-snmp is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544021" comment="php-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544014" comment="php-imap is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544015" comment="php-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544004" comment="php-bcmath is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544005" comment="php-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544036" comment="php-pdo is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544037" comment="php-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544006" comment="php-ldap is earlier than 0:5.1.6-20.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544007" comment="php-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544043" comment="php-odbc is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544044" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544047" comment="php-mysql is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544048" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544041" comment="php is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544042" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544049" comment="php-pgsql is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544050" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544045" comment="php-devel is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544046" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544053" comment="php-imap is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544054" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080544051" comment="php-ldap is earlier than 0:4.3.2-48.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544052" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080545" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0545: php security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0545-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0545.html" />
          <reference source="CVE" ref_id="CVE-2008-2051" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2051.html" />
          <reference source="CVE" ref_id="CVE-2007-5898" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5898.html" />
          <reference source="CVE" ref_id="CVE-2007-5899" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5899.html" />
          <reference source="CVE" ref_id="CVE-2007-4782" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4782.html" />
          <reference source="CVE" ref_id="CVE-2008-2107" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2107.html" />
          <reference source="CVE" ref_id="CVE-2008-2108" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2108.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

It was discovered that the PHP escapeshellcmd() function did not properly
escape multi-byte characters which are not valid in the locale used by the
script. This could allow an attacker to bypass quoting restrictions imposed
by escapeshellcmd() and execute arbitrary commands if the PHP script was
using certain locales. Scripts using the default UTF-8 locale are not
affected by this issue. (CVE-2008-2051)

The PHP functions htmlentities() and htmlspecialchars() did not properly
recognize partial multi-byte sequences. Certain sequences of bytes could be
passed through these functions without being correctly HTML-escaped.
Depending on the browser being used, an attacker could use this flaw to
conduct cross-site scripting attacks. (CVE-2007-5898)

A PHP script which used the transparent session ID configuration option, or
which used the output_add_rewrite_var() function, could leak session
identifiers to external web sites. If a page included an HTML form with an
ACTION attribute referencing a non-local URL, the user's session ID would
be included in the form data passed to that URL. (CVE-2007-5899)

It was discovered that the PHP fnmatch() function did not restrict the
length of the string argument. An attacker could use this flaw to crash the
PHP interpreter where a script used fnmatch() on untrusted input data.
(CVE-2007-4782)

It was discovered that PHP did not properly seed its pseudo-random number
generator used by functions such as rand() and mt_rand(), possibly allowing
an attacker to easily predict the generated pseudo-random values.
(CVE-2008-2107, CVE-2008-2108)

As well, these updated packages fix the following bug:

* after 2008-01-01, when using PEAR version 1.3.6 or older, it was not
possible to use the PHP Extension and Application Repository (PEAR) to
upgrade or install packages. In these updated packages, PEAR has been
upgraded to version 1.4.9, which restores support for the current
pear.php.net update server. The following changes were made to the PEAR
packages included in php-pear: Console_Getopt and Archive_Tar are now
included by default, and XML_RPC has been upgraded to version 1.5.0.

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-16" />
        <updated date="2008-07-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2051.html">CVE-2008-2051</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5898.html">CVE-2007-5898</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5899.html">CVE-2007-5899</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4782.html">CVE-2007-4782</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2107.html">CVE-2008-2107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2108.html">CVE-2008-2108</cve>
                <bugzilla href="http://bugzilla.redhat.com/263501" id="263501">fix PEAR with current pear.php.net server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/285881" id="285881">CVE-2007-4782 php crash in glob() and fnmatch() functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382411" id="382411">CVE-2007-5898 php htmlentities/htmlspecialchars multibyte sequences</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382431" id="382431">CVE-2007-5899 php session ID leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445006" id="445006">CVE-2008-2051 PHP multibyte shell escape flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445684" id="445684">CVE-2008-2107 PHP 32 bit weak random seed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445685" id="445685">CVE-2008-2108 PHP weak 64 bit random seed</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545024" comment="php-odbc is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544044" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545014" comment="php-gd is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545015" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545004" comment="php-mysql is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544048" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545002" comment="php is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544042" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545020" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545021" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545028" comment="php-mbstring is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545029" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545018" comment="php-pgsql is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544050" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545010" comment="php-devel is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544046" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545022" comment="php-ncurses is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545023" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545016" comment="php-snmp is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545017" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545012" comment="php-imap is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544054" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545008" comment="php-pear is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545009" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545026" comment="php-domxml is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080545027" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080545006" comment="php-ldap is earlier than 0:4.3.9-3.22.12" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080544052" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080547" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0547: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0547-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0547.html" />
          <reference source="CVE" ref_id="CVE-2008-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2798.html" />
          <reference source="CVE" ref_id="CVE-2008-2799" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2799.html" />
          <reference source="CVE" ref_id="CVE-2008-2800" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2800.html" />
          <reference source="CVE" ref_id="CVE-2008-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2801.html" />
          <reference source="CVE" ref_id="CVE-2008-2802" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2802.html" />
          <reference source="CVE" ref_id="CVE-2008-2803" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2803.html" />
          <reference source="CVE" ref_id="CVE-2008-2805" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2805.html" />
          <reference source="CVE" ref_id="CVE-2008-2807" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2807.html" />
          <reference source="CVE" ref_id="CVE-2008-2808" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2808.html" />
          <reference source="CVE" ref_id="CVE-2008-2809" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2809.html" />
          <reference source="CVE" ref_id="CVE-2008-2810" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2810.html" />
          <reference source="CVE" ref_id="CVE-2008-2811" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2811.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause SeaMonkey
to crash or, potentially, execute arbitrary code as the user running
SeaMonkey. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in SeaMonkey. A web page
containing malicious content could cause SeaMonkey to reveal the contents
of a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
SeaMonkey. A malicious extension could read uninitialized memory, possibly
leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way SeaMonkey escaped a listing of local file
names. If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running SeaMonkey. (CVE-2008-2808)

A flaw was found in the way SeaMonkey displayed information about
self-signed certificates. It was possible for a self-signed certificate to
contain multiple alternate name entries, which were not all displayed to
the user, allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-02" />
        <updated date="2008-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2798.html">CVE-2008-2798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2799.html">CVE-2008-2799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2800.html">CVE-2008-2800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2801.html">CVE-2008-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2802.html">CVE-2008-2802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2803.html">CVE-2008-2803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2805.html">CVE-2008-2805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2807.html">CVE-2008-2807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2808.html">CVE-2008-2808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2809.html">CVE-2008-2809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2810.html">CVE-2008-2810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2811.html">CVE-2008-2811</cve>
                <bugzilla href="http://bugzilla.redhat.com/452597" id="452597">CVE-2008-2798 Firefox malformed web content flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452598" id="452598">CVE-2008-2799 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452599" id="452599">CVE-2008-2800 Firefox XSS attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452600" id="452600">CVE-2008-2802 Firefox arbitrary JavaScript code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452602" id="452602">CVE-2008-2803 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452604" id="452604">CVE-2008-2805 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452605" id="452605">CVE-2008-2801 Firefox arbitrary signed JAR code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452709" id="452709">CVE-2008-2807 Firefox .properties memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452710" id="452710">CVE-2008-2808 Firefox file location escaping flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452711" id="452711">CVE-2008-2809 Firefox self signed certificate flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452712" id="452712">CVE-2008-2810 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453007" id="453007">CVE-2008-2811 Firefox block reflow flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547020" comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547008" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547006" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547018" comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547002" comment="seamonkey is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547004" comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547016" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547012" comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547010" comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547014" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547028" comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547030" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547027" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547024" comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547023" comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547031" comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547032" comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547029" comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547025" comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080547026" comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080549" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0549: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0549-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0549.html" />
          <reference source="CVE" ref_id="CVE-2008-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2798.html" />
          <reference source="CVE" ref_id="CVE-2008-2799" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2799.html" />
          <reference source="CVE" ref_id="CVE-2008-2800" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2800.html" />
          <reference source="CVE" ref_id="CVE-2008-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2801.html" />
          <reference source="CVE" ref_id="CVE-2008-2802" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2802.html" />
          <reference source="CVE" ref_id="CVE-2008-2803" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2803.html" />
          <reference source="CVE" ref_id="CVE-2008-2805" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2805.html" />
          <reference source="CVE" ref_id="CVE-2008-2807" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2807.html" />
          <reference source="CVE" ref_id="CVE-2008-2808" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2808.html" />
          <reference source="CVE" ref_id="CVE-2008-2809" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2809.html" />
          <reference source="CVE" ref_id="CVE-2008-2810" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2810.html" />
          <reference source="CVE" ref_id="CVE-2008-2811" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2811.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause Firefox
to crash or, potentially, execute arbitrary code as the user running
Firefox. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially-crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Firefox. A web page
containing malicious content could cause Firefox to reveal the contents of
a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
Firefox. A malicious extension could read uninitialized memory, possibly
leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Firefox escaped a listing of local file names.
If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running Firefox. (CVE-2008-2808)

A flaw was found in the way Firefox displayed information about self-signed
certificates. It was possible for a self-signed certificate to contain
multiple alternate name entries, which were not all displayed to the user,
allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

All Mozilla Firefox users should upgrade to this updated package, which
contains backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-02" />
        <updated date="2008-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2798.html">CVE-2008-2798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2799.html">CVE-2008-2799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2800.html">CVE-2008-2800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2801.html">CVE-2008-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2802.html">CVE-2008-2802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2803.html">CVE-2008-2803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2805.html">CVE-2008-2805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2807.html">CVE-2008-2807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2808.html">CVE-2008-2808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2809.html">CVE-2008-2809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2810.html">CVE-2008-2810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2811.html">CVE-2008-2811</cve>
                <bugzilla href="http://bugzilla.redhat.com/452597" id="452597">CVE-2008-2798 Firefox malformed web content flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452598" id="452598">CVE-2008-2799 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452599" id="452599">CVE-2008-2800 Firefox XSS attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452600" id="452600">CVE-2008-2802 Firefox arbitrary JavaScript code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452602" id="452602">CVE-2008-2803 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452604" id="452604">CVE-2008-2805 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452605" id="452605">CVE-2008-2801 Firefox arbitrary signed JAR code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452709" id="452709">CVE-2008-2807 Firefox .properties memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452710" id="452710">CVE-2008-2808 Firefox file location escaping flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452711" id="452711">CVE-2008-2809 Firefox self signed certificate flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452712" id="452712">CVE-2008-2810 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453007" id="453007">CVE-2008-2811 Firefox block reflow flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080549002" comment="firefox is earlier than 0:1.5.0.12-0.19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080555" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0555: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0555-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0555.html" />
          <reference source="CVE" ref_id="CVE-2008-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1187.html" />
          <reference source="CVE" ref_id="CVE-2008-1196" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1196.html" />
    
    <description>IBM's 1.4.2 SR11 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

A flaw was found in the Java XSLT processing classes. An untrusted
application or applet could cause a denial of service, or execute arbitrary
code with the permissions of the user running the JRE. (CVE-2008-1187)

A buffer overflow flaw was found in Java Web Start (JWS). An untrusted
application using the Java Network Launch Protocol (JNLP) could access
local files or execute local applications accessible to the user running
the JRE. (CVE-2008-1196) 

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain IBM's 1.4.2 SR11 Java release which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-14" />
        <updated date="2008-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1187.html">CVE-2008-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1196.html">CVE-2008-1196</cve>
                <bugzilla href="http://bugzilla.redhat.com/436030" id="436030">CVE-2008-1187 Untrusted applet and application XSLT processing privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436302" id="436302">CVE-2008-1196 Buffer overflow security vulnerabilities in Java Web Start</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555006" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555010" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555008" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132009" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080555012" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.11-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132013" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080556" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0556: freetype security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0556-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0556.html" />
          <reference source="CVE" ref_id="CVE-2008-1806" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1806.html" />
          <reference source="CVE" ref_id="CVE-2008-1807" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1807.html" />
          <reference source="CVE" ref_id="CVE-2008-1808" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1808.html" />
    
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files, as well as efficiently load, hint and render individual
glyphs.

Multiple flaws were discovered in FreeType's Printer Font Binary (PFB)
font-file format parser. If a user loaded a carefully crafted font-file
with a program linked against FreeType, it could cause the application to
crash, or possibly execute arbitrary code. (CVE-2008-1806, CVE-2008-1807,
CVE-2008-1808)

Note: the flaw in FreeType's TrueType Font (TTF) font-file format parser,
covered by CVE-2008-1808, did not affect the freetype packages as shipped
in Red Hat Enterprise Linux 3, 4, and 5, as they are not compiled with TTF
Byte Code Interpreter (BCI) support.

Users of freetype should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-06-20" />
        <updated date="2008-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1806.html">CVE-2008-1806</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1807.html">CVE-2008-1807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1808.html">CVE-2008-1808</cve>
                <bugzilla href="http://bugzilla.redhat.com/450768" id="450768">CVE-2008-1806 FreeType PFB integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450773" id="450773">CVE-2008-1807 FreeType invalid free() flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450774" id="450774">CVE-2008-1808 FreeType off-by-one flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452474" id="452474">Latest freetype erratum does not display all fonts</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556002" comment="freetype is earlier than 0:2.2.1-20.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556003" comment="freetype is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556006" comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556007" comment="freetype-demos is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556004" comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556005" comment="freetype-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556011" comment="freetype-utils is earlier than 0:2.1.4-10.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556012" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556009" comment="freetype is earlier than 0:2.1.4-10.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556010" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556015" comment="freetype-demos is earlier than 0:2.1.4-10.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556016" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556013" comment="freetype-devel is earlier than 0:2.1.4-10.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556014" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556020" comment="freetype-utils is earlier than 0:2.1.9-8.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556012" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556018" comment="freetype is earlier than 0:2.1.9-8.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556010" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556019" comment="freetype-demos is earlier than 0:2.1.9-8.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556016" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080556021" comment="freetype-devel is earlier than 0:2.1.9-8.el4.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080556014" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080561" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0561: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0561-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0561.html" />
          <reference source="CVE" ref_id="CVE-2008-2662" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2662.html" />
          <reference source="CVE" ref_id="CVE-2008-2663" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2663.html" />
          <reference source="CVE" ref_id="CVE-2008-2664" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2664.html" />
          <reference source="CVE" ref_id="CVE-2008-2725" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2725.html" />
          <reference source="CVE" ref_id="CVE-2008-2726" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2726.html" />
          <reference source="CVE" ref_id="CVE-2008-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2376.html" />
    
    <description>Ruby is an interpreted scripting language for quick and easy
object-oriented programming.

Multiple integer overflows leading to a heap overflow were discovered in
the array- and string-handling code used by Ruby. An attacker could use
these flaws to crash a Ruby application or, possibly, execute arbitrary
code with the privileges of the Ruby application using untrusted inputs in
array or string operations. (CVE-2008-2376, CVE-2008-2662, CVE-2008-2663,
CVE-2008-2725, CVE-2008-2726)

It was discovered that Ruby used the alloca() memory allocation function in
the format (%) method of the String class without properly restricting
maximum string length. An attacker could use this flaw to crash a Ruby
application or, possibly, execute arbitrary code with the privileges of the
Ruby application using long, untrusted strings as format strings.
(CVE-2008-2664)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting these issues.

Users of Ruby should upgrade to these updated packages, which contain a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-14" />
        <updated date="2008-07-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2662.html">CVE-2008-2662</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2663.html">CVE-2008-2663</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2664.html">CVE-2008-2664</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2725.html">CVE-2008-2725</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2726.html">CVE-2008-2726</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2376.html">CVE-2008-2376</cve>
                <bugzilla href="http://bugzilla.redhat.com/450821" id="450821">CVE-2008-2662 ruby: Integer overflows in rb_str_buf_append()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450825" id="450825">CVE-2008-2663 ruby: Integer overflows in rb_ary_store()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450834" id="450834">CVE-2008-2664 ruby: Unsafe use of alloca in rb_str_format()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451821" id="451821">CVE-2008-2725 ruby: integer overflow in rb_ary_splice/update/replace() - REALLOC_N</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451828" id="451828">CVE-2008-2726 ruby: integer overflow in rb_ary_splice/update/replace() - beg + rlen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453589" id="453589">CVE-2008-2376 ruby: integer overflows in rb_ary_fill() / Array#fill</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561014" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561015" comment="ruby-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561004" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561005" comment="ruby-ri is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561008" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561009" comment="ruby-mode is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561018" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561019" comment="ruby-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561012" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561013" comment="ruby-tcltk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561006" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561007" comment="ruby-irb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561010" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561011" comment="ruby-rdoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561002" comment="ruby is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561003" comment="ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561016" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561017" comment="ruby-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561031" comment="irb is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561032" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561027" comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561028" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561025" comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561026" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561033" comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561034" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561029" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561030" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561021" comment="ruby is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561022" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080561023" comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561024" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080562" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0562: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0562-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0562.html" />
          <reference source="CVE" ref_id="CVE-2008-2663" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2663.html" />
          <reference source="CVE" ref_id="CVE-2008-2664" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2664.html" />
          <reference source="CVE" ref_id="CVE-2008-2725" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2725.html" />
          <reference source="CVE" ref_id="CVE-2008-2726" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2726.html" />
          <reference source="CVE" ref_id="CVE-2006-6303" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-6303.html" />
          <reference source="CVE" ref_id="CVE-2008-2376" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2376.html" />
    
    <description>Ruby is an interpreted scripting language for quick and easy
object-oriented programming.

Multiple integer overflows leading to a heap overflow were discovered in
the array- and string-handling code used by Ruby. An attacker could use
these flaws to crash a Ruby application or, possibly, execute arbitrary
code with the privileges of the Ruby application using untrusted inputs in
array or string operations. (CVE-2008-2376, CVE-2008-2663, CVE-2008-2725,
CVE-2008-2726)

It was discovered that Ruby used the alloca() memory allocation function in
the format (%) method of the String class without properly restricting
maximum string length. An attacker could use this flaw to crash a Ruby
application or, possibly, execute arbitrary code with the privileges of the
Ruby application using long, untrusted strings as format strings.
(CVE-2008-2664)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting these issues.

A flaw was discovered in the way Ruby's CGI module handles certain HTTP
requests. A remote attacker could send a specially crafted request and
cause the Ruby CGI script to enter an infinite loop, possibly causing a
denial of service. (CVE-2006-6303)

Users of Ruby should upgrade to these updated packages, which contain a
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-14" />
        <updated date="2008-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2663.html">CVE-2008-2663</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2664.html">CVE-2008-2664</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2725.html">CVE-2008-2725</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2726.html">CVE-2008-2726</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-6303.html">CVE-2006-6303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2376.html">CVE-2008-2376</cve>
                <bugzilla href="http://bugzilla.redhat.com/218287" id="218287">CVE-2006-6303 ruby's cgi.rb vulnerable infinite loop DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450825" id="450825">CVE-2008-2663 ruby: Integer overflows in rb_ary_store()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450834" id="450834">CVE-2008-2664 ruby: Unsafe use of alloca in rb_str_format()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451821" id="451821">CVE-2008-2725 ruby: integer overflow in rb_ary_splice/update/replace() - REALLOC_N</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451828" id="451828">CVE-2008-2726 ruby: integer overflow in rb_ary_splice/update/replace() - beg + rlen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453589" id="453589">CVE-2008-2376 ruby: integer overflows in rb_ary_fill() / Array#fill</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562014" comment="ruby-docs is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561028" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562010" comment="irb is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561032" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562008" comment="ruby-mode is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561026" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562006" comment="ruby-libs is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561034" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562004" comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561030" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562002" comment="ruby is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561022" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080562012" comment="ruby-devel is earlier than 0:1.6.8-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561024" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080569" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0569: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0569-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0569.html" />
          <reference source="CVE" ref_id="CVE-2008-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2798.html" />
          <reference source="CVE" ref_id="CVE-2008-2799" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2799.html" />
          <reference source="CVE" ref_id="CVE-2008-2800" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2800.html" />
          <reference source="CVE" ref_id="CVE-2008-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2801.html" />
          <reference source="CVE" ref_id="CVE-2008-2802" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2802.html" />
          <reference source="CVE" ref_id="CVE-2008-2803" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2803.html" />
          <reference source="CVE" ref_id="CVE-2008-2805" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2805.html" />
          <reference source="CVE" ref_id="CVE-2008-2807" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2807.html" />
          <reference source="CVE" ref_id="CVE-2008-2808" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2808.html" />
          <reference source="CVE" ref_id="CVE-2008-2809" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2809.html" />
          <reference source="CVE" ref_id="CVE-2008-2810" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2810.html" />
          <reference source="CVE" ref_id="CVE-2008-2811" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2811.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Multiple flaws were found in the processing of malformed JavaScript
content. A web page containing such malicious content could cause Firefox
to crash or, potentially, execute arbitrary code as the user running
Firefox. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially-crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Firefox. A web page
containing malicious content could cause Firefox to reveal the contents of
a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
Firefox. A malicious extension could read uninitialized memory, possibly
leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Firefox escaped a listing of local file names.
If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running Firefox. (CVE-2008-2808)

A flaw was found in the way Firefox displayed information about self-signed
certificates. It was possible for a self-signed certificate to contain
multiple alternate name entries, which were not all displayed to the user,
allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

All Mozilla Firefox users should upgrade to these updated packages, which
contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-02" />
        <updated date="2008-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2798.html">CVE-2008-2798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2799.html">CVE-2008-2799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2800.html">CVE-2008-2800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2801.html">CVE-2008-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2802.html">CVE-2008-2802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2803.html">CVE-2008-2803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2805.html">CVE-2008-2805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2807.html">CVE-2008-2807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2808.html">CVE-2008-2808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2809.html">CVE-2008-2809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2810.html">CVE-2008-2810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2811.html">CVE-2008-2811</cve>
                <bugzilla href="http://bugzilla.redhat.com/452597" id="452597">CVE-2008-2798 Firefox malformed web content flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452598" id="452598">CVE-2008-2799 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452599" id="452599">CVE-2008-2800 Firefox XSS attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452600" id="452600">CVE-2008-2802 Firefox arbitrary JavaScript code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452602" id="452602">CVE-2008-2803 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452604" id="452604">CVE-2008-2805 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452605" id="452605">CVE-2008-2801 Firefox arbitrary signed JAR code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452709" id="452709">CVE-2008-2807 Firefox .properties memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452710" id="452710">CVE-2008-2808 Firefox file location escaping flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452711" id="452711">CVE-2008-2809 Firefox self signed certificate flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452712" id="452712">CVE-2008-2810 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453007" id="453007">CVE-2008-2811 Firefox block reflow flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569006" comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569007" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569002" comment="xulrunner is earlier than 0:1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569004" comment="xulrunner-devel is earlier than 0:1.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569008" comment="yelp is earlier than 0:2.16.0-19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569009" comment="yelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569010" comment="devhelp is earlier than 0:0.12-17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569011" comment="devhelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569012" comment="devhelp-devel is earlier than 0:0.12-17.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569013" comment="devhelp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080569014" comment="firefox is earlier than 0:3.0-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080575" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0575: rdesktop security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0575-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0575.html" />
          <reference source="CVE" ref_id="CVE-2008-1801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1801.html" />
          <reference source="CVE" ref_id="CVE-2008-1803" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1803.html" />
    
    <description>rdesktop is an open source client for Microsoft Windows NT Terminal Server
and Microsoft Windows 2000 and 2003 Terminal Services, capable of natively
using the Remote Desktop Protocol (RDP) to present the user's NT desktop.
No additional server extensions are required.

An integer underflow and integer signedness issue were discovered in the
rdesktop. If an attacker could convince a victim to connect to a malicious
RDP server, the attacker could cause the victim's rdesktop to crash or,
possibly, execute an arbitrary code. (CVE-2008-1801, CVE-2008-1803)

Users of rdesktop should upgrade to these updated packages, which contain a
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1801.html">CVE-2008-1801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1803.html">CVE-2008-1803</cve>
                <bugzilla href="http://bugzilla.redhat.com/445825" id="445825">CVE-2008-1801 rdesktop: iso_recv_msg() Integer Underflow Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445829" id="445829">CVE-2008-1803 rdesktop: channel_process() Integer Signedness Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080575002" comment="rdesktop is earlier than 0:1.4.1-6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080575003" comment="rdesktop is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080576" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0576: rdesktop security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0576-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0576.html" />
          <reference source="CVE" ref_id="CVE-2008-1801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1801.html" />
    
    <description>rdesktop is an open source client for Microsoft Windows NT Terminal Server
and Microsoft Windows 2000 and 2003 Terminal Services, capable of natively
using the Remote Desktop Protocol (RDP) to present the user's NT desktop.
No additional server extensions are required.

An integer underflow vulnerability was discovered in the rdesktop. If an
attacker could convince a victim to connect to a malicious RDP server, the
attacker could cause the victim's rdesktop to crash or, possibly, execute
an arbitrary code. (CVE-2008-1801)

Users of rdesktop should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1801.html">CVE-2008-1801</cve>
                <bugzilla href="http://bugzilla.redhat.com/445825" id="445825">CVE-2008-1801 rdesktop: iso_recv_msg() Integer Underflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080576002" comment="rdesktop is earlier than 0:1.2.0-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080576003" comment="rdesktop is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080579" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0579: vsftpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0579-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0579.html" />
          <reference source="CVE" ref_id="CVE-2008-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2375.html" />
    
    <description>vsftpd (Very Secure File Transfer Protocol (FTP) daemon) is a secure FTP
server for Linux and Unix-like systems.

The version of vsftpd as shipped in Red Hat Enterprise Linux 3 when used in
combination with Pluggable Authentication Modules (PAM) had a memory leak
on an invalid authentication attempt. Since vsftpd prior to version 2.0.5
allows any number of invalid attempts on the same connection this memory
leak could lead to an eventual DoS. (CVE-2008-2375)

This update mitigates this security issue by including a backported patch
which terminates a session after a given number of failed log in attempts.
The default number of attempts is 3 and this can be configured using the
"max_login_fails" directive.

All vsftpd users should upgrade to this updated package, which addresses
this vulnerability.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2375.html">CVE-2008-2375</cve>
                <bugzilla href="http://bugzilla.redhat.com/453376" id="453376">CVE-2008-2375 older vsftpd authentication memory leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080579002" comment="vsftpd is earlier than 0:1.2.1-3E.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080579003" comment="vsftpd is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080580" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0580: vim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0580-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0580.html" />
          <reference source="CVE" ref_id="CVE-2007-2953" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2953.html" />
          <reference source="CVE" ref_id="CVE-2008-2712" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2712.html" />
          <reference source="CVE" ref_id="CVE-2008-3074" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3074.html" />
          <reference source="CVE" ref_id="CVE-2008-3075" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3075.html" />
          <reference source="CVE" ref_id="CVE-2008-4101" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4101.html" />
          <reference source="CVE" ref_id="CVE-2008-6235" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6235.html" />
    
    <description>Vim (Visual editor IMproved) is an updated and improved version of the vi
editor.

Several input sanitization flaws were found in Vim's keyword and tag
handling. If Vim looked up a document's maliciously crafted tag or keyword,
it was possible to execute arbitrary code as the user running Vim.
(CVE-2008-4101)

Multiple security flaws were found in netrw.vim, the Vim plug-in providing
file reading and writing over the network. If a user opened a specially
crafted file or directory with the netrw plug-in, it could result in
arbitrary code execution as the user running Vim. (CVE-2008-3076)

A security flaw was found in zip.vim, the Vim plug-in that handles ZIP
archive browsing. If a user opened a ZIP archive using the zip.vim plug-in,
it could result in arbitrary code execution as the user running Vim.
(CVE-2008-3075)

A security flaw was found in tar.vim, the Vim plug-in which handles TAR
archive browsing. If a user opened a TAR archive using the tar.vim plug-in,
it could result in arbitrary code execution as the user runnin Vim.
(CVE-2008-3074)

Several input sanitization flaws were found in various Vim system
functions. If a user opened a specially crafted file, it was possible to
execute arbitrary code as the user running Vim. (CVE-2008-2712)

Ulf Härnhammar, of Secunia Research, discovered a format string flaw in
Vim's help tag processor. If a user was tricked into executing the
"helptags" command on malicious data, arbitrary code could be executed with
the permissions of the user running Vim. (CVE-2007-2953)

All Vim users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-25" />
        <updated date="2008-11-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2953.html">CVE-2007-2953</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2712.html">CVE-2008-2712</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3074.html">CVE-2008-3074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3075.html">CVE-2008-3075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4101.html">CVE-2008-4101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6235.html">CVE-2008-6235</cve>
                <bugzilla href="http://bugzilla.redhat.com/248542" id="248542">CVE-2007-2953 vim format string flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451759" id="451759">CVE-2008-2712 vim: command execution via scripts not sanitizing inputs to execute and system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461927" id="461927">CVE-2008-4101 vim: arbitrary code execution in commands: K, Control-], g]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467428" id="467428">CVE-2008-3074 Vim tar.vim plugin: improper Implementation of shellescape() (arbitrary code execution)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467432" id="467432">CVE-2008-3075 Vim zip.vim plugin: improper Implementation of shellescape() (arbitrary code execution)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467439" id="467439">CVE-2008-6235 Vim netrw.vim plugin: lack of sanitization throughout netrw.vim can lead to arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080580006" comment="vim-minimal is earlier than 2:7.0.109-4.el5_2.4z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080580007" comment="vim-minimal is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080580002" comment="vim is earlier than 2:7.0.109-4.el5_2.4z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080580003" comment="vim is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080580008" comment="vim-X11 is earlier than 2:7.0.109-4.el5_2.4z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080580009" comment="vim-X11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080580004" comment="vim-common is earlier than 2:7.0.109-4.el5_2.4z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080580005" comment="vim-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080580010" comment="vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080580011" comment="vim-enhanced is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080581" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0581: bluez-libs and bluez-utils security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0581-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0581.html" />
          <reference source="CVE" ref_id="CVE-2008-2374" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2374.html" />
    
    <description>The bluez-libs package contains libraries for use in Bluetooth
applications. The bluez-utils package contains Bluetooth daemons and utilities.

An input validation flaw was found in the Bluetooth Session Description
Protocol (SDP) packet parser used by the Bluez Bluetooth utilities. A
Bluetooth device with an already-established trust relationship, or a local
user registering a service record via a UNIX® socket or D-Bus interface,
could cause a crash, or possibly execute arbitrary code with privileges of
the hcid daemon. (CVE-2008-2374)

Users of bluez-libs and bluez-utils are advised to upgrade to these updated
packages, which contains a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-14" />
        <updated date="2008-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2374.html">CVE-2008-2374</cve>
                <bugzilla href="http://bugzilla.redhat.com/452715" id="452715">CVE-2008-2374 bluez-libs: SDP payload processing vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581004" comment="bluez-libs-devel is earlier than 0:3.7-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581005" comment="bluez-libs-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581002" comment="bluez-libs is earlier than 0:3.7-1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581003" comment="bluez-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581008" comment="bluez-utils-cups is earlier than 0:3.7-2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581009" comment="bluez-utils-cups is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581006" comment="bluez-utils is earlier than 0:3.7-2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581007" comment="bluez-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581013" comment="bluez-libs-devel is earlier than 0:2.10-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581014" comment="bluez-libs-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581011" comment="bluez-libs is earlier than 0:2.10-3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581012" comment="bluez-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581017" comment="bluez-utils-cups is earlier than 0:2.10-2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581018" comment="bluez-utils-cups is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080581015" comment="bluez-utils is earlier than 0:2.10-2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080581016" comment="bluez-utils is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080583" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0583: openldap security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0583-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0583.html" />
          <reference source="CVE" ref_id="CVE-2008-2952" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2952.html" />
    
    <description>OpenLDAP is an open source suite of Lightweight Directory Access Protocol
(LDAP) applications and development tools. LDAP is a set of protocols for
accessing directory services.

A denial of service flaw was found in the way the OpenLDAP slapd daemon
processed certain network messages. An unauthenticated remote attacker
could send a specially crafted request that would crash the slapd daemon.
(CVE-2008-2952)

Users of openldap should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-09" />
        <updated date="2008-07-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2952.html">CVE-2008-2952</cve>
                <bugzilla href="http://bugzilla.redhat.com/453444" id="453444">CVE-2008-2952 OpenLDAP denial-of-service flaw in ASN.1 decoder</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583006" comment="openldap-devel is earlier than 0:2.3.27-8.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110011" comment="openldap-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583010" comment="openldap-clients is earlier than 0:2.3.27-8.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110005" comment="openldap-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583004" comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110007" comment="openldap-servers-sql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583008" comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110009" comment="compat-openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583002" comment="openldap is earlier than 0:2.3.27-8.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110003" comment="openldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583012" comment="openldap-servers is earlier than 0:2.3.27-8.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110013" comment="openldap-servers is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583017" comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110024" comment="openldap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583023" comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110020" comment="openldap-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583019" comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110022" comment="openldap-servers-sql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583021" comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110018" comment="compat-openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583015" comment="openldap is earlier than 0:2.2.13-8.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110016" comment="openldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080583025" comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080110026" comment="openldap-servers is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080584" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0584: pidgin security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0584-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0584.html" />
          <reference source="CVE" ref_id="CVE-2008-2927" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2927.html" />
    
    <description>Pidgin is a multi-protocol Internet Messaging client.

An integer overflow flaw was found in Pidgin's MSN protocol handler. If a
user received a malicious MSN message, it was possible to execute arbitrary
code with the permissions of the user running Pidgin. (CVE-2008-2927)

Note: the default Pidgin privacy setting only allows messages from users in
the buddy list. This prevents arbitrary MSN users from exploiting this
flaw.

This update also addresses the following bug:

* when attempting to connect to the ICQ network, Pidgin would fail to
connect, present an alert saying the "The client version you are using is
too old", and de-activate the ICQ account. This update restores Pidgin's
ability to connect to the ICQ network.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-09" />
        <updated date="2008-07-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2927.html">CVE-2008-2927</cve>
                <bugzilla href="http://bugzilla.redhat.com/453634" id="453634">RHEL5 - Fix ICQ login</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453764" id="453764">CVE-2008-2927 pidgin MSN integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453773" id="453773">RHEL4 - Fix ICQ login</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453774" id="453774">RHEL3 - Fix ICQ login</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584014" comment="libpurple is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584015" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584010" comment="finch is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584011" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584004" comment="libpurple-perl is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584005" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584002" comment="pidgin is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584018" comment="pidgin-devel is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584016" comment="pidgin-perl is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584017" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584012" comment="libpurple-devel is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584013" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584008" comment="finch-devel is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584009" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080584006" comment="libpurple-tcl is earlier than 0:2.3.1-2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584007" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584021" comment="pidgin is earlier than 0:1.5.1-2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584022" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584024" comment="pidgin is earlier than 0:1.5.1-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584022" comment="pidgin is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080594" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0594: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0594-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0594.html" />
          <reference source="CVE" ref_id="CVE-2008-3103" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3103.html" />
          <reference source="CVE" ref_id="CVE-2008-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3104.html" />
          <reference source="CVE" ref_id="CVE-2008-3105" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3105.html" />
          <reference source="CVE" ref_id="CVE-2008-3106" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3106.html" />
          <reference source="CVE" ref_id="CVE-2008-3107" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3107.html" />
          <reference source="CVE" ref_id="CVE-2008-3109" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3109.html" />
          <reference source="CVE" ref_id="CVE-2008-3110" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3110.html" />
          <reference source="CVE" ref_id="CVE-2008-3112" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3112.html" />
          <reference source="CVE" ref_id="CVE-2008-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3114.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language. 

A vulnerability was found in the Java Management Extensions (JMX)
management agent, when local monitoring is enabled. This allowed remote
attackers to perform illegal operations. (CVE-2008-3103)

Multiple vulnerabilities with unsigned applets were reported. A remote
attacker could misuse an unsigned applet to connect to localhost services
running on the host running the applet. (CVE-2008-3104)

Several vulnerabilities in the Java API for XML Web Services (JAX-WS)
client and service implementation were found. A remote attacker who caused
malicious XML to be processed by a trusted or untrusted application was
able access URLs or cause a denial of service. (CVE-2008-3105, CVE-2008-3106)

A JRE vulnerability could be triggered by an untrusted application or
applet. A remote attacker could grant an untrusted applet or application
extended privileges such as being able to read and write local files, or
execute local programs. (CVE-2008-3107)

Several vulnerabilities within the JRE scripting support were reported. A
remote attacker could grant an untrusted applet extended privileges such as
reading and writing local files, executing local programs, or querying the
sensitive data of other applets. (CVE-2008-3109, CVE-2008-3110)

A vulnerability in Java Web Start was found. A remote attacker was able to
create arbitrary files with the permissions of the user running the
untrusted Java Web Start application. (CVE-2008-3112)

Another vulnerability in Java Web Start when processing untrusted
applications was reported. An attacker was able to acquire sensitive
information, such as the cache location. (CVE-2008-3114)

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-14" />
        <updated date="2008-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3103.html">CVE-2008-3103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3104.html">CVE-2008-3104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3105.html">CVE-2008-3105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3106.html">CVE-2008-3106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3107.html">CVE-2008-3107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3109.html">CVE-2008-3109</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3110.html">CVE-2008-3110</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3112.html">CVE-2008-3112</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3114.html">CVE-2008-3114</cve>
                <bugzilla href="http://bugzilla.redhat.com/452649" id="452649">CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452658" id="452658">CVE-2008-3107 JDK untrusted applet/application privilege escalation (6661918)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452659" id="452659">CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454603" id="454603">CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454606" id="454606">CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454608" id="454608">CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location  (6704074)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080594004" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.7-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594005" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080594002" comment="java-1.6.0-sun is earlier than 1:1.6.0.7-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080594010" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.7-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594011" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080594012" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.7-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594013" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080594008" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.7-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594009" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080594006" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.7-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594007" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080595" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0595: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0595-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0595.html" />
          <reference source="CVE" ref_id="CVE-2008-3103" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3103.html" />
          <reference source="CVE" ref_id="CVE-2008-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3104.html" />
          <reference source="CVE" ref_id="CVE-2008-3107" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3107.html" />
          <reference source="CVE" ref_id="CVE-2008-3111" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3111.html" />
          <reference source="CVE" ref_id="CVE-2008-3112" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3112.html" />
          <reference source="CVE" ref_id="CVE-2008-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3113.html" />
          <reference source="CVE" ref_id="CVE-2008-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3114.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language. 

A vulnerability was found in the Java Management Extensions (JMX)
management agent, when local monitoring is enabled. This allowed remote
attackers to perform illegal operations. (CVE-2008-3103)

Multiple vulnerabilities with unsigned applets were reported. A remote
attacker could misuse an unsigned applet to connect to localhost services
running on the host running the applet. (CVE-2008-3104)

A Java Runtime Environment (JRE) vulnerability could be triggered by an
untrusted application or applet. A remote attacker could grant an untrusted
applet extended privileges such as reading and writing local files, or
executing local programs. (CVE-2008-3107)

Several buffer overflow vulnerabilities in Java Web Start were reported.
These vulnerabilities may allow an untrusted Java Web Start application to
elevate its privileges and thereby grant itself permission to read and/or
write local files, as well as to execute local applications accessible to
the user running the untrusted application. (CVE-2008-3111)

Two file processing vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start application, was able to
create or delete arbitrary files with the permissions of the user running
the untrusted application. (CVE-2008-3112, CVE-2008-3113)

A vulnerability in Java Web Start when processing untrusted applications
was reported. An attacker was able to acquire sensitive information, such
as the cache location. (CVE-2008-3114) 

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-14" />
        <updated date="2008-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3103.html">CVE-2008-3103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3104.html">CVE-2008-3104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3107.html">CVE-2008-3107</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3111.html">CVE-2008-3111</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3112.html">CVE-2008-3112</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3113.html">CVE-2008-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3114.html">CVE-2008-3114</cve>
                <bugzilla href="http://bugzilla.redhat.com/452658" id="452658">CVE-2008-3107 JDK untrusted applet/application privilege escalation (6661918)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452659" id="452659">CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454605" id="454605">CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454606" id="454606">CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454607" id="454607">CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454608" id="454608">CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location  (6704074)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080595012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080595002" comment="java-1.5.0-sun is earlier than 0:1.5.0.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080595006" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123011" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080595008" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080595004" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123009" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080595010" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.16-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123005" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080597" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0597: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0597-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0597.html" />
          <reference source="CVE" ref_id="CVE-2008-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2785.html" />
          <reference source="CVE" ref_id="CVE-2008-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2933.html" />
          <reference source="CVE" ref_id="CVE-2008-3198" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3198.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

An integer overflow flaw was found in the way Firefox displayed certain web
content. A malicious web site could cause Firefox to crash, or execute
arbitrary code with the permissions of the user running Firefox.
(CVE-2008-2785)

A flaw was found in the way Firefox handled certain command line URLs. If
another application passed Firefox a malformed URL, it could result in
Firefox executing local malicious content with chrome privileges.
(CVE-2008-2933)

All firefox users should upgrade to these updated packages, which contain
Firefox 3.0.1 that corrects these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-16" />
        <updated date="2008-07-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2785.html">CVE-2008-2785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2933.html">CVE-2008-2933</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3198.html">CVE-2008-3198</cve>
                <bugzilla href="http://bugzilla.redhat.com/452204" id="452204">CVE-2008-2785 mozilla: CSS reference counter overflow (ZDI-CAN-349)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454697" id="454697">CVE-2008-2933 Firefox command line URL launches multi-tabs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597002" comment="devhelp is earlier than 0:0.12-18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569011" comment="devhelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597004" comment="devhelp-devel is earlier than 0:0.12-18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569013" comment="devhelp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597010" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569007" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597006" comment="xulrunner is earlier than 0:1.9.0.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597008" comment="xulrunner-devel is earlier than 0:1.9.0.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597012" comment="yelp is earlier than 0:2.16.0-20.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569009" comment="yelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597014" comment="firefox is earlier than 0:3.0.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080597016" comment="nspluginwrapper is earlier than 0:0.9.91.5-22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080597017" comment="nspluginwrapper is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080598" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0598: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0598-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0598.html" />
          <reference source="CVE" ref_id="CVE-2008-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2785.html" />
          <reference source="CVE" ref_id="CVE-2008-2933" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2933.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

An integer overflow flaw was found in the way Firefox displayed certain web
content. A malicious web site could cause Firefox to crash, or execute
arbitrary code with the permissions of the user running Firefox.
(CVE-2008-2785)

A flaw was found in the way Firefox handled certain command line URLs. If
another application passed Firefox a malformed URL, it could result in
Firefox executing local malicious content with chrome privileges.
(CVE-2008-2933)

All firefox users should upgrade to this updated package, which contains
backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-16" />
        <updated date="2008-07-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2785.html">CVE-2008-2785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2933.html">CVE-2008-2933</cve>
                <bugzilla href="http://bugzilla.redhat.com/452204" id="452204">CVE-2008-2785 mozilla: CSS reference counter overflow (ZDI-CAN-349)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454697" id="454697">CVE-2008-2933 Firefox command line URL launches multi-tabs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080598002" comment="firefox is earlier than 0:1.5.0.12-0.21.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080599" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0599: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0599-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0599.html" />
          <reference source="CVE" ref_id="CVE-2008-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2785.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

An integer overflow flaw was found in the way SeaMonkey displayed certain
web content. A malicious web site could cause SeaMonkey to crash or execute
arbitrary code with the permissions of the user running SeaMonkey.
(CVE-2008-2785)

All seamonkey users should upgrade to these updated packages, which contain
a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-16" />
        <updated date="2008-07-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2785.html">CVE-2008-2785</cve>
                <bugzilla href="http://bugzilla.redhat.com/452204" id="452204">CVE-2008-2785 mozilla: CSS reference counter overflow (ZDI-CAN-349)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599006" comment="seamonkey-nspr is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599008" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599014" comment="seamonkey-mail is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599002" comment="seamonkey is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599020" comment="seamonkey-devel is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599018" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599016" comment="seamonkey-chat is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599004" comment="seamonkey-nss is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599010" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.22.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599031" comment="seamonkey-nspr is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599032" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599027" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599025" comment="seamonkey-mail is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599023" comment="seamonkey is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599028" comment="seamonkey-devel is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599030" comment="seamonkey-nss is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599029" comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599024" comment="seamonkey-chat is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599026" comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.4.el4_6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599033" comment="devhelp is earlier than 0:0.10-0.8.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080599034" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080599035" comment="devhelp-devel is earlier than 0:0.10-0.8.1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080599036" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080607" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0607: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0607-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0607.html" />
          <reference source="CVE" ref_id="CVE-2008-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2136.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issue:

* a possible kernel memory leak was found in the Linux kernel Simple
Internet Transition (SIT) INET6 implementation. This could allow a local
unprivileged user to cause a denial of service. (CVE-2008-2136, Important)

As well, these updated packages fix the following bugs:

* a possible kernel hang on hugemem systems, due to a bug in NFS, which may
have caused systems to become unresponsive, has been resolved.

* an inappropriate exit condition occurred in the architecture-specific
"mmap()" realization, which fell into an infinite loop under certain
conditions. On 64-bit systems, this issue may have manifested itself to
users as a soft lockup, or process hangs.

* due to a bug in hardware initialization in the "ohci_hcd" kernel module,
the kernel may have failed with a NULL pointer dereference. On 64-bit
PowerPC systems, this may have caused booting to fail, and drop to xmon. On
other platforms, a kernel oops occurred.

* due to insufficient locks in task termination code, a panic may have
occurred in the "sys_times()" system call on SMP machines.

Red Hat Enterprise Linux 4 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-23" />
        <updated date="2008-07-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2136.html">CVE-2008-2136</cve>
                <bugzilla href="http://bugzilla.redhat.com/446031" id="446031">CVE-2008-2136 kernel: sit memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450185" id="450185">[RHEL 4] cffimtgsaslx08 hung</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450760" id="450760">Patch for bug 360281 "Odd behaviour in mmap" introduces regression</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450865" id="450865">kernel failed to boot and dropped to xmon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455072" id="455072">kernel panic with  kernel version 2.6.9-67.0.20.EL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607002" comment="kernel is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607022" comment="kernel-doc is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607004" comment="kernel-devel is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607008" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607018" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607010" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607014" comment="kernel-xenU is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607006" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080607012" comment="kernel-smp is earlier than 0:2.6.9-67.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080612" version="504" class="patch">
      <metadata>
        <title>RHSA-2008:0612: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0612-03" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0612.html" />
          <reference source="CVE" ref_id="CVE-2008-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2136.html" />
          <reference source="CVE" ref_id="CVE-2008-1294" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1294.html" />
          <reference source="CVE" ref_id="CVE-2008-2812" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2812.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a possible kernel memory leak was found in the Linux kernel Simple
Internet Transition (SIT) INET6 implementation. This could allow a local
unprivileged user to cause a denial of service. (CVE-2008-2136, Important)

* a flaw was found in the Linux kernel setrlimit system call, when setting
RLIMIT_CPU to a certain value. This could allow a local unprivileged user
to bypass the CPU time limit. (CVE-2008-1294, Moderate)

* multiple NULL pointer dereferences were found in various Linux kernel
network drivers. These drivers were missing checks for terminal validity,
which could allow privilege escalation. (CVE-2008-2812, Moderate)

These updated packages fix the following bugs:

* the GNU libc stub resolver is a minimal resolver that works with Domain
Name System (DNS) servers to satisfy requests from applications for names.
The GNU libc stub resolver did not specify a source UDP port, and therefore
used predictable port numbers. This could have made DNS spoofing attacks
easier.

The Linux kernel has been updated to implement random UDP source ports
where none are specified by an application. This allows applications, such
as those using the GNU libc stub resolver, to use random UDP source ports,
helping to make DNS spoofing attacks harder.

* when using certain hardware, a bug in UART_BUG_TXEN may have caused
incorrect hardware detection, causing data flow to "/dev/ttyS1" to hang.

* a 50-75% drop in NFS server rewrite performance, compared to Red Hat
Enterprise Linux 4.6, has been resolved.

* due a bug in the fast userspace mutex code, while one thread fetched a
pointer, another thread may have removed it, causing the first thread to
fetch the wrong pointer, possibly causing a system crash.

* on certain Hitachi hardware, removing the "uhci_hcd" module caused a
kernel oops, and the following error:

BUG: warning at arch/ia64/kernel/iosapic.c:1001/iosapic_unregister_intr()

Even after the "uhci_hcd" module was reloaded, there was no access to USB
devices. As well, on systems that have legacy interrupts,
"acpi_unregister_gsi" incorrectly called "iosapci_unregister_intr()",
causing warning messages to be logged.

* when a page was mapped with mmap(), and "PROT_WRITE" was the only
"prot" argument, the first read of that page caused a segmentation fault.
If the page was read after it was written to, no fault occurred. This was
incompatible with the Red Hat Enterprise Linux 4 behavior.

* due to a NULL pointer dereference in powernowk8_init(), a panic may
have occurred.

* certain error conditions handled by the bonding sysfs interface could
have left rtnl_lock() unbalanced, either by locking and returning without
unlocking, or by unlocking when it did not lock, possibly causing a
"kernel: RTNL: assertion failed at net/core/fib_rules.c" error.

* the kernel currently expects a maximum of six Machine Check Exception
(MCE) banks to be exposed by a CPU. Certain CPUs have 7 or more, which may
have caused the MCE to be incorrectly reported.

* a race condition in UNIX domain sockets may have caused recv() to return
zero. For clusters, this may have caused unexpected failovers.

* msgrcv() frequently returned an incorrect "ERESTARTNOHAND (514)" error
number.

* on certain Intel Itanium-based systems, when kdump was configured to halt
the system after a dump operation, after the "System halted." output, the
kernel continued to output endless "soft lockup" messages.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-04" />
        <updated date="2008-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2136.html">CVE-2008-2136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1294.html">CVE-2008-1294</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2812.html">CVE-2008-2812</cve>
                <bugzilla href="http://bugzilla.redhat.com/437114" id="437114">CVE-2008-1294 kernel: setrlimit(RLIMIT_CPUINFO) with zero value doesn't inherit properly across children</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443071" id="443071">[Stratus 5.2.z][1/2] ttyS1 lost interrupt and it stops transmitting [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446031" id="446031">CVE-2008-2136 kernel: sit memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448685" id="448685">50-75 % drop in nfs-server rewrite performance compared to rhel 4.6+ [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450336" id="450336">Kernel crash on futex [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450337" id="450337">[RHEL5] BUG: warning at arch/ia64/kernel/iosapic.c:1001/iosapic_unregiste</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450758" id="450758">mmap() with PROT_WRITE on RHEL5 incompatible with RHEL4.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450866" id="450866">RHEL 5.3 NULL pointer dereferenced in powernowk8_init</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451939" id="451939">bonding driver can leave rtnl_lock unbalanced</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451941" id="451941">RHEL 5.3 extend MCE banks support for Dunnington, Nehalem, and beyond</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452231" id="452231">[RHEL5.1] In unix domain sockets, recv() may incorrectly return zero</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453419" id="453419">CVE-2008-2812 kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454566" id="454566">kernel: randomize udp port allocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455256" id="455256">[Stratus 5.2.z][2/2] ttyS1 lost interrupt and it stops transmitting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455278" id="455278">The msgrcv() syscall fails with error number 514 (ERESTARTNOHAND).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456117" id="456117">[REG][5.3] Soft lockup is detected</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612004" comment="kernel-headers is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612002" comment="kernel is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612024" comment="kernel-doc is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612020" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612014" comment="kernel-devel is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612010" comment="kernel-debug is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612016" comment="kernel-kdump is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612012" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612006" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612022" comment="kernel-PAE is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612018" comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080612008" comment="kernel-xen is earlier than 0:2.6.18-92.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080616" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0616: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0616-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0616.html" />
          <reference source="CVE" ref_id="CVE-2008-2785" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2785.html" />
          <reference source="CVE" ref_id="CVE-2008-2798" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2798.html" />
          <reference source="CVE" ref_id="CVE-2008-2799" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2799.html" />
          <reference source="CVE" ref_id="CVE-2008-2800" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2800.html" />
          <reference source="CVE" ref_id="CVE-2008-2801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2801.html" />
          <reference source="CVE" ref_id="CVE-2008-2802" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2802.html" />
          <reference source="CVE" ref_id="CVE-2008-2803" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2803.html" />
          <reference source="CVE" ref_id="CVE-2008-2805" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2805.html" />
          <reference source="CVE" ref_id="CVE-2008-2807" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2807.html" />
          <reference source="CVE" ref_id="CVE-2008-2808" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2808.html" />
          <reference source="CVE" ref_id="CVE-2008-2809" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2809.html" />
          <reference source="CVE" ref_id="CVE-2008-2810" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2810.html" />
          <reference source="CVE" ref_id="CVE-2008-2811" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2811.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Multiple flaws were found in the processing of malformed JavaScript
content. An HTML mail containing such malicious content could cause
Thunderbird to crash or, potentially, execute arbitrary code as the user
running Thunderbird. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803)

Several flaws were found in the processing of malformed HTML content. An
HTML mail containing malicious content could cause Thunderbird to crash or,
potentially, execute arbitrary code as the user running Thunderbird.
(CVE-2008-2785, CVE-2008-2798, CVE-2008-2799, CVE-2008-2811)

Several flaws were found in the way malformed HTML content was displayed.
An HTML mail containing specially-crafted content could, potentially, trick
a Thunderbird user into surrendering sensitive information. (CVE-2008-2800)

Two local file disclosure flaws were found in Thunderbird. An HTML mail
containing malicious content could cause Thunderbird to reveal the contents
of a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810)

A flaw was found in the way a malformed .properties file was processed by
Thunderbird. A malicious extension could read uninitialized memory,
possibly leaking sensitive data to the extension. (CVE-2008-2807)

A flaw was found in the way Thunderbird escaped a listing of local file
names. If a user could be tricked into listing a local directory containing
malicious file names, arbitrary JavaScript could be run with the
permissions of the user running Thunderbird. (CVE-2008-2808)

A flaw was found in the way Thunderbird displayed information about
self-signed certificates. It was possible for a self-signed certificate to
contain multiple alternate name entries, which were not all displayed to
the user, allowing them to mistakenly extend trust to an unknown site.
(CVE-2008-2809)

Note: JavaScript support is disabled by default in Thunderbird. The above
issues are not exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-23" />
        <updated date="2008-07-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2785.html">CVE-2008-2785</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2798.html">CVE-2008-2798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2799.html">CVE-2008-2799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2800.html">CVE-2008-2800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2801.html">CVE-2008-2801</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2802.html">CVE-2008-2802</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2803.html">CVE-2008-2803</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2805.html">CVE-2008-2805</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2807.html">CVE-2008-2807</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2808.html">CVE-2008-2808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2809.html">CVE-2008-2809</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2810.html">CVE-2008-2810</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2811.html">CVE-2008-2811</cve>
                <bugzilla href="http://bugzilla.redhat.com/452204" id="452204">CVE-2008-2785 mozilla: CSS reference counter overflow (ZDI-CAN-349)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452597" id="452597">CVE-2008-2798 Firefox malformed web content flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452598" id="452598">CVE-2008-2799 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452599" id="452599">CVE-2008-2800 Firefox XSS attacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452600" id="452600">CVE-2008-2802 Firefox arbitrary JavaScript code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452602" id="452602">CVE-2008-2803 Firefox javascript arbitrary code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452604" id="452604">CVE-2008-2805 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452605" id="452605">CVE-2008-2801 Firefox arbitrary signed JAR code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452709" id="452709">CVE-2008-2807 Firefox .properties memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452710" id="452710">CVE-2008-2808 Firefox file location escaping flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452711" id="452711">CVE-2008-2809 Firefox self signed certificate flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452712" id="452712">CVE-2008-2810 Firefox arbitrary file disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453007" id="453007">CVE-2008-2811 Firefox block reflow flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080616002" comment="thunderbird is earlier than 0:2.0.0.16-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080616005" comment="thunderbird is earlier than 0:1.5.0.12-14.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080617" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0617: vim security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0617-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0617.html" />
          <reference source="CVE" ref_id="CVE-2007-2953" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2953.html" />
          <reference source="CVE" ref_id="CVE-2008-2712" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2712.html" />
          <reference source="CVE" ref_id="CVE-2008-3432" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3432.html" />
          <reference source="CVE" ref_id="CVE-2008-4101" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4101.html" />
    
    <description>Vim (Visual editor IMproved) is an updated and improved version of the vi
editor.

Several input sanitization flaws were found in Vim's keyword and tag
handling. If Vim looked up a document's maliciously crafted tag or keyword,
it was possible to execute arbitrary code as the user running Vim.
(CVE-2008-4101)

A heap-based overflow flaw was discovered in Vim's expansion of file name
patterns with shell wildcards. An attacker could create a specially-crafted
file or directory name that, when opened by Vim, caused the application to
crash or, possibly, execute arbitrary code. (CVE-2008-3432)

Several input sanitization flaws were found in various Vim system
functions. If a user opened a specially crafted file, it was possible to
execute arbitrary code as the user running Vim. (CVE-2008-2712)

Ulf Härnhammar, of Secunia Research, discovered a format string flaw in
Vim's help tag processor. If a user was tricked into executing the
"helptags" command on malicious data, arbitrary code could be executed with
the permissions of the user running Vim. (CVE-2007-2953)

All Vim users are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-25" />
        <updated date="2008-11-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2953.html">CVE-2007-2953</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2712.html">CVE-2008-2712</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3432.html">CVE-2008-3432</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4101.html">CVE-2008-4101</cve>
                <bugzilla href="http://bugzilla.redhat.com/248542" id="248542">CVE-2007-2953 vim format string flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451759" id="451759">CVE-2008-2712 vim: command execution via scripts not sanitizing inputs to execute and system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455455" id="455455">CVE-2008-3432 vim: heap buffer overflow in mch_expand_wildcards()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461927" id="461927">CVE-2008-4101 vim: arbitrary code execution in commands: K, Control-], g]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617004" comment="vim-minimal is earlier than 1:6.3.046-0.30E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617005" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617002" comment="vim is earlier than 1:6.3.046-0.30E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617010" comment="vim-X11 is earlier than 1:6.3.046-0.30E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617006" comment="vim-common is earlier than 1:6.3.046-0.30E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617007" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617008" comment="vim-enhanced is earlier than 1:6.3.046-0.30E.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617016" comment="vim-minimal is earlier than 1:6.3.046-1.el4_7.5z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617005" comment="vim-minimal is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617013" comment="vim is earlier than 1:6.3.046-1.el4_7.5z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617003" comment="vim is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617015" comment="vim-X11 is earlier than 1:6.3.046-1.el4_7.5z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617011" comment="vim-X11 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617014" comment="vim-common is earlier than 1:6.3.046-1.el4_7.5z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617007" comment="vim-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080617017" comment="vim-enhanced is earlier than 1:6.3.046-1.el4_7.5z" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080617009" comment="vim-enhanced is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080641" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0641: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0641-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0641.html" />
          <reference source="CVE" ref_id="CVE-2008-0883" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0883.html" />
          <reference source="CVE" ref_id="CVE-2008-2641" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2641.html" />
    
    <description>Adobe Acrobat Reader allows users to view and print documents in Portable
Document Format (PDF).

An input validation flaw was discovered in a JavaScript engine used by
Acrobat Reader. A malicious PDF file could cause Acrobat Reader to crash
or, potentially, execute arbitrary code as the user running Acrobat Reader.
(CVE-2008-2641)

An insecure temporary file usage issue was discovered in the Acrobat Reader
"acroread" startup script. A local attacker could potentially overwrite
arbitrary files that were writable by the user running Acrobat Reader, if
the victim ran "acroread" with certain command line arguments.
(CVE-2008-0883)

All acroread users are advised to upgrade to these updated packages, that
contain Acrobat Reader version 8.1.2 Security Update 1, and are not
vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-21" />
        <updated date="2008-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0883.html">CVE-2008-0883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2641.html">CVE-2008-2641</cve>
                <bugzilla href="http://bugzilla.redhat.com/436263" id="436263">CVE-2008-0883 acroread: insecure handling of temporary files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452632" id="452632">CVE-2008-2641 acroread: input validation issue in a JavaScript method</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080641004" comment="acroread-plugin is earlier than 0:8.1.2.SU1-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080144005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080641002" comment="acroread is earlier than 0:8.1.2.SU1-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080144003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080648" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0648: tomcat security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0648-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0648.html" />
          <reference source="CVE" ref_id="CVE-2008-1232" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1232.html" />
          <reference source="CVE" ref_id="CVE-2008-1947" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1947.html" />
          <reference source="CVE" ref_id="CVE-2008-2370" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2370.html" />
          <reference source="CVE" ref_id="CVE-2008-2938" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2938.html" />
    
    <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

A cross-site scripting vulnerability was discovered in the
HttpServletResponse.sendError() method. A remote attacker could inject
arbitrary web script or HTML via forged HTTP headers. (CVE-2008-1232)

An additional cross-site scripting vulnerability was discovered in the host
manager application. A remote attacker could inject arbitrary web script or
HTML via the hostname parameter. (CVE-2008-1947)

A traversal vulnerability was discovered when using a RequestDispatcher
in combination with a servlet or JSP. A remote attacker could utilize a
specially-crafted request parameter to access protected web resources.
(CVE-2008-2370)

An additional traversal vulnerability was discovered when the
"allowLinking" and "URIencoding" settings were activated. A remote attacker
could use a UTF-8-encoded request to extend their privileges and obtain
local files accessible to the Tomcat process. (CVE-2008-2938)

Users of tomcat should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-27" />
        <updated date="2008-08-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1232.html">CVE-2008-1232</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1947.html">CVE-2008-1947</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2370.html">CVE-2008-2370</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2938.html">CVE-2008-2938</cve>
                <bugzilla href="http://bugzilla.redhat.com/446393" id="446393">CVE-2008-1947 Tomcat host manager xss - name field</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456120" id="456120">CVE-2008-2938 tomcat Unicode directory traversal vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457597" id="457597">CVE-2008-1232 tomcat: Cross-Site-Scripting enabled by sendError call</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457934" id="457934">CVE-2008-2370 tomcat RequestDispatcher information disclosure vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648008" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042005" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648004" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042013" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648010" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042023" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648016" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042017" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648018" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042007" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648006" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042021" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648012" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042009" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648022" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042015" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648020" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042011" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648014" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042019" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080648002" comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080042003" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080649" version="504" class="patch">
      <metadata>
        <title>RHSA-2008:0649: libxslt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0649-03" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0649.html" />
          <reference source="CVE" ref_id="CVE-2008-2935" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2935.html" />
    
    <description>libxslt is a library for transforming XML files into other XML files using
the standard XSLT stylesheet transformation mechanism.

A heap buffer overflow flaw was discovered in the RC4 libxslt library
extension. An attacker could create a malicious XSL file that would cause a
crash, or, possibly, execute arbitrary code with the privileges of the
application using the libxslt library to perform XSL transformations on
untrusted XSL style sheets. (CVE-2008-2935)

Red Hat would like to thank Chris Evans for reporting this vulnerability.

All libxslt users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-31" />
        <updated date="2008-07-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2935.html">CVE-2008-2935</cve>
                <bugzilla href="http://bugzilla.redhat.com/455848" id="455848">CVE-2008-2935 libxslt: buffer overflow in libexslt RC4 encryption/decryption functions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080649006" comment="libxslt-devel is earlier than 0:1.1.17-2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287007" comment="libxslt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080649004" comment="libxslt-python is earlier than 0:1.1.17-2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287005" comment="libxslt-python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080649002" comment="libxslt is earlier than 0:1.1.17-2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287003" comment="libxslt is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080649013" comment="libxslt-devel is earlier than 0:1.1.11-1.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287014" comment="libxslt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080649011" comment="libxslt-python is earlier than 0:1.1.11-1.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287012" comment="libxslt-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080649009" comment="libxslt is earlier than 0:1.1.11-1.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080287010" comment="libxslt is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080665" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0665: Updated kernel packages for Red Hat Enterprise Linux 4.7 (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0665-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0665.html" />
          <reference source="CVE" ref_id="CVE-2006-4145" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4145.html" />
          <reference source="CVE" ref_id="CVE-2008-2812" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2812.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Kernel Feature Support: 
* iostat displays I/O performance for partitions
* I/O task accounting added to getrusage(), allowing comprehensive core
statistics
* page cache pages count added to show_mem() output
* tux O_ATOMICLOOKUP flag removed from the open() system call: replaced
with O_CLOEXEC
* the kernel now exports process limit information to /proc/[PID]/limits
* implement udp_poll() to reduce likelihood of false positives returned
from select()
* the TCP_RTO_MIN parameter can now be configured to a maximum of 3000
milliseconds. This is configured using "ip route"
* update CIFS to version 1.50

Added Features:
* nfs.enable_ino64 boot command line parameter: enable and disable 32-bit
inode numbers when using NFS
* tick "divider" kernel boot parameter: reduce CPU overhead, and increase
efficiency at the cost of lowering timing accuracy
* /proc/sys/vm/nfs-writeback-lowmem-only tunable parameter: resolve NFS
read performance
* /proc/sys/vm/write-mapped tunable option, allowing the option of faster
NFS reads
* support for Large Receive Offload as a networking module
* core dump masking, allowing a core dump process to skip the shared memory
segments of a process

Virtualization:
* para-virtualized network and block device drivers, to increase
fully-virtualized guest performance
* support for more than three VNIF numbers per guest domain

Platform Support:
* AMD ATI SB800 SATA controller, AMD ATI SB600 and SB700 40-pin IDE cable
* 64-bit DMA support on AMD ATI SB700
* PCI device IDs to support Intel ICH10
* /dev/msr[0-n] device files
* powernow-k8 as a module
* SLB shadow buffer support for IBM POWER6 systems
* support for CPU frequencies greater than 32-bit on IBM POWER5, IBM POWER6
* floating point load and store handler for IBM POWER6

Added Drivers and Updates:
* ixgbe 1.1.18, for the Intel 82598 10GB ethernet controller
* bnx2x 1.40.22, for network adapters on the Broadcom 5710 chipset
* dm-hp-sw 1.0.0, for HP Active/Standby
* zfcp version and bug fixes
* qdio to fix FCP/SCSI write I/O expiring on LPARs
* cio bug fixes
* eHEA latest upstream, and netdump and netconsole support
* ipr driver support for dual SAS RAID controllers
* correct CPU cache info and SATA support for Intel Tolapai
* i5000_edac support for Intel 5000 chipsets
* i3000_edac support for Intel 3000 and 3010 chipsets
* add i2c_piix4 module on 64-bit systems to support AMD ATI SB600, 700
and 800
* i2c-i801 support for Intel Tolapai
* qla4xxx: 5.01.01-d2 to 5.01.02-d4-rhel4.7-00
* qla2xxx: 8.01.07-d4 to 8.01.07-d4-rhel4.7-02
* cciss: 2.6.16 to 2.6.20
* mptfusion: 3.02.99.00rh to 3.12.19.00rh
* lpfc:0: 8.0.16.34 to 8.0.16.40
* megaraid_sas: 00.00.03.13 to 00.00.03.18-rh1
* stex: 3.0.0.1 to  3.6.0101.2
* arcmsr: 1.20.00.13 to 1.20.00.15.rh4u7
* aacraid: 1.1-5[2441] to 1.1.5[2455]

Miscellaneous Updates:
* OFED 1.3 support
* wacom driver to add support for Cintiq 20WSX, Wacom Intuos3 12x19, 12x12
and 4x6 tablets
* sata_svw driver to support Broadcom HT-1100 chipsets
* libata to un-blacklist Hitachi drives to enable NCQ
* ide driver allows command line option to disable ide drivers
* psmouse support for cortps protocol

These updated packages fix the following security issues:

* NULL pointer access due to missing checks for terminal validity.
(CVE-2008-2812, Moderate)

* a security flaw was found in the Linux kernel Universal Disk Format file
system. (CVE-2006-4145, Low)

For further details, refer to the latest Red Hat Enterprise Linux 4.7
release notes: redhat.com/docs/manuals/enterprise</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4145.html">CVE-2006-4145</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2812.html">CVE-2008-2812</cve>
                <bugzilla href="http://bugzilla.redhat.com/151085" id="151085">mount are not interruptible</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/166038" id="166038">ext2online can't resize: No space left on device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/171712" id="171712">A NFS export mounted using version 4 and TCP shows up as UDP in /proc/mounts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/179201" id="179201">pvmove causes kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183119" id="183119">Assertion failure in journal_next_log_block</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185202" id="185202">Kernel build requires "High Memory Support"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/186606" id="186606">Incorrect suggestion on when to install largesmp kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/194585" id="194585">mdadm --grow -n 2 (old: 3) fails on particular raid1 devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/195685" id="195685">RFE: Add dm-hp-sw to kernel to allow use of active/passive sans with dm multipathing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/204309" id="204309">kernel retries portmap query indefinitely when statd is down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/205966" id="205966">Firewall - Premature ip_conntrack timer expiry on 3+ ack or window size advertisements - (hanging tomcat threads problem)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/206113" id="206113">[PATCH][RHEL4U4] Fix estimate-mistake (e820-memory-hole and numnodes) of available_memory in x86_64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/212321" id="212321">[PATCH][RHEL4U4] Backported udp_poll() function (Fix the problem that select() returns in RHEL4 though select() must not return essentially when kernel receives broken UDP packet(s))</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/212922" id="212922">/sbin/service iptables stop hangs on modprobe -r ipt_state</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/219639" id="219639">Crash dump fails on IA64 with block_order set to 10</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/227610" id="227610">READDIR on a NFSv4 directory containing a referral returns -EIO for entire directory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233234" id="233234">Missing definition for mutex_destroy in linux/kernel.h</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247446" id="247446">RHEL4-U5: "cdrom open failed" message in /var/log/messages on every reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/247879" id="247879">dm-mirror: spinlock in write_callback has the potential for deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248488" id="248488">Backport divider= option from RHEL5 U1 to RHEL4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248787" id="248787">[RHEL4 U4] NFS server, rpciod was stuck in a infinite loop,</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248954" id="248954">Oracle ASM DBWR process goes into 100% CPU spin when using hugepages on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249727" id="249727">xenbus has use-after-free in drivers/xen/xenbus/xenbus_xs.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250381" id="250381">xenbus suspend_mutex remains locked after transaction failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250842" id="250842">oopses when multicasting with connection oriented socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/251560" id="251560">[Promise 4.7 feat] Update stex driver to version 3.6.0101.2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252222" id="252222">ipv6 device reference counting error in net/ipv6/anycast.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252287" id="252287">AMD/ATI SB600/700/800 use same SMBus controller devID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252400" id="252400">RHEL4 U5: ia64 machine hang when DB starts using rac/nfs/hugepages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/252939" id="252939">Long Delay before OOMKill launches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253592" id="253592">[RHEL 4.5] forcedeth: pull latest upstream updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/270661" id="270661">need a way to disable ide drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/278961" id="278961">epoll_wait(..., -100) results in printk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/280431" id="280431">ip_tables reference count will underflow occasionally</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/287741" id="287741">PCI: hotplug: acpiphp: avoid acpiphp "cannot get bridge info" PCI hotplug failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/299901" id="299901">We need SB800 SATA Controller supported in RHEL4.7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/300861" id="300861">sb600 system generates ATA errors during initscripts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/306911" id="306911">CVE-2006-4145 UDF truncating issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/309081" id="309081">i386 compressed diskdump header contains incorrect panic cpu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/311431" id="311431">kernel BUG at mm/rmap.c:479 during suspend/resume testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/311881" id="311881">ptrace: i386 debugger + x86_64 kernel + threaded (i386) inferior = error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/335361" id="335361">RHEL 4.7: SB700 contains two IDE channels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/337671" id="337671">[RHEL4] Patch pata_jmicron to support new controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/351911" id="351911">RHEL4.6:  AD1984 HDAudio does not work on AMD Trevally Board(RS690 + SB700)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/354371" id="354371">readdir on nfs4 passing non-posix errors to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/355141" id="355141">pull upstream patches for smbfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/359651" id="359651">[PATCH] nfsv4 fails to update content of files when open for write</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/359671" id="359671">RHEL4: Hald causes system deadlock on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/360311" id="360311">kernel dm: panic on shrinking device size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/361931" id="361931">[Stratus 4.7 bug] iounmap may sleep while holding vmlist_lock, causing a deadlock.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/364361" id="364361">NFS: Fix directory caching problem - with test case and patch.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/377351" id="377351">kernel dm: bd_mount_sem counter corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/377371" id="377371">kernel dm crypt: oops on device removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/377611" id="377611">Marvell NIC using skge driver loses promiscuous mode on rewiring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/381221" id="381221">Assertion failure in journal_start() at fs/jbd/transaction.c:274: 'handle->h_transaction->t_journal == journal'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/393501" id="393501">execve returning EFBIG when running 4 GB executable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396081" id="396081">Since "Patch2037: linux-2.6.9-vm-balance.patch" my NFS performance is poorly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/402581" id="402581">Deadlock while performing nfs operations.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/414131" id="414131">Checksum offloading and IP connection tracking don't play well together</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/424541" id="424541">Please build SMBus driver i2c-piix4 as a module in RHEL4.7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/424871" id="424871">Implement netif_release_rx_bufs for copying receiver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425721" id="425721">[QLogic 4.7 bug][3/5] qla4xxx - Targets not seen on first port (5.01.02-d2 --> 5.01.02-d3)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426031" id="426031">rapid block device plug / unplug leads to kernel crash and/or soft lockup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426301" id="426301">FEAT: RHEL 4.7 Intel Tolapai cpucache patch</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426411" id="426411">[QLogic 4.7 Bug][5/5] qla2xxx - avoid delay for loop ready when loop dead</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426647" id="426647">ptrace: PTRACE_SINGLESTEP,signal steps on the 2nd instr.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427204" id="427204">RHEL4, make tcp_input_metrics() get minimum RTO via tcp_rto_min()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427544" id="427544">Update CIFS to 1.50cRH for 4.7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427799" id="427799">[RHEL-4] RFE: Add EDAC driver for Intel 3000/3010 chipsets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428801" id="428801">[Areca 4.7 feat] Update the arcmsr driver to 1.20.00.15.RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428934" id="428934">Can not send redirect packet when jiffiess wraparound</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428964" id="428964">RHEL4.7: HDMI Audio support for AMD ATI chipsets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429103" id="429103">Allocations on resume path can cause deadlock due to attempting to swap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429930" id="429930">Fake ARP dropped after migration leading to loss of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430313" id="430313">[QLogic 4.7 bug][4/5] qla4xxx - Race condition fixes w/ constant qla3xxx ifup/ifdown (5.01.02-d3 --> 5.01.02-d4)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430494" id="430494">[NetApp-S 4.7 bug] LUN removal status is not updated on the host without a driver reload</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430946" id="430946">nfs server sending short packets on nfsv2 UDP readdir replies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431081" id="431081">[RHEL4.6]: Under load, an i386 PV guest on i386 HV will hang during save/restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433249" id="433249">[EMC 4.7 bug] nfs_access_cache_shrinker() race with umount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433524" id="433524">oProfile Driver Module Patch for Family10h</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435000" id="435000">ptrace: ERESTARTSYS from calling a function from a debugger</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435351" id="435351">[RHEL4.7]: PV kernel can OOPs during live migrate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435787" id="435787">RHEL4.7: USB stress test failure on AMD SBX00</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437423" id="437423">Add Xen disk and network paravirtualized drivers to bare-metal kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437865" id="437865">[RHEL 4.6] bonding 802.3ad does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438027" id="438027">RHEL4.6 Diskdump performance regression (mptfusion)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438115" id="438115">Add invocation of weak-modules on kernel install/remove</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438688" id="438688">68.25 Kernel rpm installation/uninstallation errors out</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438723" id="438723">32bit NFS server returns -EIO for readdirplus request when backing file system has 32bit inodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438834" id="438834">cluster mirrors should not be attempted when cmirror modules are not loaded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438975" id="438975">gettimeofday is not monotonically increasing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439109" id="439109">[Broadcom 4.7 bug] HT1000 chip based systems getting blacklisted for msi</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439539" id="439539">RHEL4 kernel ignores extended cpu model field</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439540" id="439540">oprofile fix to support Penryn-based processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439926" id="439926">do not limit locked memory when RLIMIT_MEMLOCK is RLIM_INFINITY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441445" id="441445">[QLogic 4.7 feat] Update qla2xxx - qla84xx variant support.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442124" id="442124">bonding: incorrect backport creates possible incorrect interface flags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442298" id="442298">Memory corruption due to VNIF increase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442538" id="442538">kernel panic in gnttab_map when booting RHEL4 x86_64 FV xen guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442789" id="442789">oops in cifs module while trying to stop a thread (kthread_stop) during filesystem mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443052" id="443052">kernel failed to boot and dropped to xmon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443053" id="443053">cciss driver crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443825" id="443825">ls shows two /proc/[pid]/limits files for every process</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444473" id="444473">Fake ARP dropped after migration leading to loss of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446409" id="446409">RHEL4 U6 hang in epoll_wait</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447315" id="447315">parted error: Can't open /dev/xvda while probing disks during installation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448641" id="448641">[QLogic 4.7 bug] qla2xxx - Update firmware for 4, 8 Gb/S adapters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448934" id="448934">Patch for bug 435280 introduces possibility of dead lock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449381" id="449381">System hangs when using /proc/sys/vm/drop_caches under heavy load on large system.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450094" id="450094">Patch for bug 360281 "Odd behaviour in mmap" introduces regression</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450645" id="450645">[QLogic 4.7 bug] qla2xxx- several fixes: ioctl module and slab corruption (8.02.09-d0-rhel4.7-04)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450918" id="450918">vmware - Console graphic problem when mouse is moved</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453419" id="453419">CVE-2008-2812 kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665002" comment="kernel is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665022" comment="kernel-doc is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665004" comment="kernel-devel is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665006" comment="kernel-smp-devel is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665020" comment="kernel-hugemem is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665014" comment="kernel-largesmp is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665012" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665016" comment="kernel-xenU is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665010" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080665008" comment="kernel-smp is earlier than 0:2.6.9-78.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080680" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0680: vsftpd security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0680-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0680.html" />
          <reference source="CVE" ref_id="CVE-2008-2375" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2375.html" />
    
    <description>vsftpd (Very Secure File Transfer Protocol (FTP) daemon) is a secure FTP
server for Linux and Unix-like systems.

The version of vsftpd as shipped in Red Hat Enterprise Linux 4 when used in
combination with Pluggable Authentication Modules (PAM) had a memory leak
on an invalid authentication attempt. Since vsftpd prior to version 2.0.5
allows any number of invalid attempts on the same connection this memory
leak could lead to an eventual DoS. (CVE-2008-2375)

This update mitigates this security issue by including a backported patch
which terminates a session after a given number of failed log in attempts.
The default number of attempts is 3 and this can be configured using the
"max_login_fails" directive.

This package also addresses the following bugs:

* when uploading unique files, a bug in vsftpd caused the file to be saved
with a suffix '.1' even when no previous file with that name existed. This
issues is resolved in this package.

* when vsftpd was run through the init script, it was possible for the init
script to print an 'OK' message, even though the vsftpd may not have
started. The init script no longer produces a false verification with this
update.

* vsftpd only supported usernames with a maximum length of 32 characters.
The updated package now supports usernames up to 128 characters long.

* a system flaw meant vsftpd output could become dependent on the timing or
sequence of other events, even when the "lock_upload_files" option was set.
If a file, filename.ext, was being uploaded and a second transfer of the
file, filename.ext, was started before the first transfer was finished, the
resultant uploaded file was a corrupt concatenation of the latter upload
and the tail of the earlier upload. With this updated package, vsftpd
allows the earlier upload to complete before overwriting with the latter
upload, fixing the issue.

* the 'lock_upload_files' option was not documented in the manual page. A
new manual page describing this option is included in this package.

* vsftpd did not support usernames that started with an underscore or a
period character. These special characters are now allowed at the beginning
of a username.

* when storing a unique file, vsftpd could cause an error for some clients.
This is rectified in this package.

* vsftpd init script was found to not be Linux Standards Base compliant.
This update corrects their exit codes to conform to the standard.

All vsftpd users are advised to upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2375.html">CVE-2008-2375</cve>
                <bugzilla href="http://bugzilla.redhat.com/197141" id="197141">vsftpd 2.0.1 memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/206843" id="206843">vsftpd is checked wrongly in init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/236326" id="236326">maximum username length too short</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240550" id="240550">vsftpd has a create/lock race condition which corrupts uploads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250727" id="250727">Uploaded file corrupted when two connections from same client uploading same file simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/316381" id="316381">lock_upload_files not documented in vsftpd.conf man page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/408431" id="408431">Memory leak in pattern matching function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431450" id="431450">Wrong init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453376" id="453376">CVE-2008-2375 older vsftpd authentication memory leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080680002" comment="vsftpd is earlier than 0:2.0.1-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080579003" comment="vsftpd is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080715" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0715: nss_ldap security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0715-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0715.html" />
          <reference source="CVE" ref_id="CVE-2007-5794" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5794.html" />
    
    <description>The nss_ldap package contains the nss_ldap and pam_ldap modules. The
nss_ldap module is a plug-in which allows applications to retrieve
information about users and groups from a directory server. The pam_ldap
module allows PAM-aware applications to use a directory server to verify
user passwords.

A race condition was discovered in nss_ldap, which affected certain
applications that make LDAP connections, such as Dovecot. This could cause
nss_ldap to answer a request for information about one user with the
information about a different user. (CVE-2007-5794)

As well, this updated package fixes the following bugs:

* in certain situations, on Itanium(R) architectures, when an application
performed an LDAP lookup for a highly populated group, for example,
containing more than 150 members, the application crashed, or may have
caused a segmentation fault. As well, this issue may have caused commands,
such as "ls", to return a "ber_free_buf: Assertion" error.

* when an application enumerated members of a netgroup, the nss_ldap
module returned a successful status result and the netgroup name, even
when the netgroup did not exist. This behavior was not consistent with
other modules. In this updated package, nss_ldap no longer returns a
successful status when the netgroup does not exist.

* in master and slave server environments, with systems that were
configured to use a read-only directory server, if user log in attempts
were denied because their passwords had expired, and users attempted to
immediately change their passwords, the replication server returned an LDAP
referral, instructing the pam_ldap module to resissue its request to a
different server; however, the pam_ldap module failed to do so. In these
situations, an error such as the following occurred:

LDAP password information update failed: Can't contact LDAP server
Insufficient 'write' privilege to the 'userPassword' attribute of entry
[entry]

In this updated package, password changes are allowed when binding against
a slave server, which resolves this issue.

* when a system used a directory server for naming information, and
"nss_initgroups_ignoreusers root" was configured in "/etc/ldap.conf",
dbus-daemon-1 would hang. Running the "service messagebus start" command
did not start the service, and it did not fail, which would stop the boot
process if it was not cancelled.

As well, this updated package upgrades nss_ldap to the version as shipped
with Red Hat Enterprise Linux 5.

Users of nss_ldap are advised to upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5794.html">CVE-2007-5794</cve>
                <bugzilla href="http://bugzilla.redhat.com/155187" id="155187">CVE-2007-5794 nss_ldap randomly replying with wrong user's data [rhel-4.7]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233382" id="233382">nss_ldap crashes on large groups (IA64)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253997" id="253997">nss_ldap / setnetgrent() returns always 1 despite not retrieving any valid results.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/367461" id="367461">CVE-2007-5794 nss_ldap randomly replying with wrong user's data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/401731" id="401731">Rebase nss_ldap to RHEL 5.2 version</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429101" id="429101">dbus-daemon-1 hangs when using the option nss_initgroups_ignoreusers in /etc/ldap.conf with the user root</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080715002" comment="nss_ldap is earlier than 0:253-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080715003" comment="nss_ldap is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080725" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0725: rdesktop security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0725-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0725.html" />
          <reference source="CVE" ref_id="CVE-2008-1801" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1801.html" />
    
    <description>rdesktop is an open source client for Microsoft Windows NT Terminal Server
and Microsoft Windows 2000 and 2003 Terminal Services, capable of natively
using the Remote Desktop Protocol (RDP) to present the user's NT desktop.
No additional server extensions are required.

An integer underflow vulnerability was discovered in the rdesktop. If an
attacker could convince a victim to connect to a malicious RDP server, the
attacker could cause the victim's rdesktop to crash or, possibly, execute
an arbitrary code. (CVE-2008-1801)

Additionally, the following bug was fixed:

A missing command line option caused rdesktop to fail when using the krdc
remote desktop utility. Using krdc to connect to a terminal server resulted
in errors such as the following:

The version of rdesktop you are using ([version]) is too old:

rdesktop [version] or greater is required. A working patch for rdesktop
[version] can be found in KDE CVS.

In this updated package, krdc successfully connects to terminal servers.

Users of rdesktop should upgrade to these updated packages, which contain a
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-04-16" />
        <updated date="2008-07-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1801.html">CVE-2008-1801</cve>
                <bugzilla href="http://bugzilla.redhat.com/164462" id="164462">krdc requires rdesktop > 1.3.1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445825" id="445825">CVE-2008-1801 rdesktop: iso_recv_msg() Integer Underflow Vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080725002" comment="rdesktop is earlier than 0:1.3.1-9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080576003" comment="rdesktop is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080768" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0768: mysql security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0768-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0768.html" />
          <reference source="CVE" ref_id="CVE-2006-3469" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-3469.html" />
          <reference source="CVE" ref_id="CVE-2006-4031" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4031.html" />
          <reference source="CVE" ref_id="CVE-2007-2691" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2691.html" />
          <reference source="CVE" ref_id="CVE-2008-2079" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2079.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. MySQL is a
client/server implementation consisting of a server daemon (mysqld), and
many different client programs and libraries.

MySQL did not correctly check directories used as arguments for the DATA
DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated
attacker could elevate their access privileges to tables created by other
database users. Note: this attack does not work on existing tables. An
attacker can only elevate their access to another user's tables as the
tables are created. As well, the names of these created tables need to be
predicted correctly for this attack to succeed. (CVE-2008-2079)

MySQL did not require the "DROP" privilege for "RENAME TABLE" statements.
An authenticated user could use this flaw to rename arbitrary tables.
(CVE-2007-2691)

MySQL allowed an authenticated user to access a table through a previously
created MERGE table, even after the user's privileges were revoked from the
original table, which might violate intended security policy. This is
addressed by allowing the MERGE storage engine to be disabled, which can be
done by running mysqld with the "--skip-merge" option. (CVE-2006-4031)

A flaw in MySQL allowed an authenticated user to cause the MySQL daemon to
crash via crafted SQL queries. This only caused a temporary denial of
service, as the MySQL daemon is automatically restarted after the crash.
(CVE-2006-3469)

As well, these updated packages fix the following bugs:

* in the previous mysql packages, if a column name was referenced more
than once in an "ORDER BY" section of a query, a segmentation fault
occurred.

* when MySQL failed to start, the init script returned a successful (0)
exit code. When using the Red Hat Cluster Suite, this may have caused
cluster services to report a successful start, even when MySQL failed to
start. In these updated packages, the init script returns the correct exit
codes, which resolves this issue.

* it was possible to use the mysqld_safe command to specify invalid port
numbers (higher than 65536), causing invalid ports to be created, and, in
some cases, a "port number definition: unsigned short" error. In these
updated packages, when an invalid port number is specified, the default
port number is used.

* when setting "myisam_repair_threads > 1", any repair set the index
cardinality to "1", regardless of the table size.

* the MySQL init script no longer runs "chmod -R" on the entire database
directory tree during every startup.

* when running "mysqldump" with the MySQL 4.0 compatibility mode option,
"--compatible=mysql40", mysqldump created dumps that omitted the
"auto_increment" field.

As well, the MySQL init script now uses more reliable methods for
determining parameters, such as the data directory location.

Note: these updated packages upgrade MySQL to version 4.1.22. For a full
list of bug fixes and enhancements, refer to the MySQL release notes:
http://dev.mysql.com/doc/refman/4.1/en/news-4-1-22.html

All mysql users are advised to upgrade to these updated packages, which
resolve these issues and add this enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-3469.html">CVE-2006-3469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4031.html">CVE-2006-4031</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2691.html">CVE-2007-2691</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2079.html">CVE-2008-2079</cve>
                <bugzilla href="http://bugzilla.redhat.com/201904" id="201904">CVE-2006-3469 mysql server DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/201988" id="201988">Queries using a column name multiple times in ORDER BY crash mysql</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/202246" id="202246">CVE-2006-4031 MySQL improper permission revocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/221085" id="221085">chown -R of the mysql data directory every startup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233771" id="233771">RFE+patch: MySQLd "init.d" startup script should rely on "/usr/bin/my_print_defaults" to get at options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/241688" id="241688">CVE-2007-2691 mysql DROP privilege not enforced when renaming tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445222" id="445222">CVE-2008-2079 mysql: privilege escalation via DATA/INDEX DIRECTORY directives</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080768002" comment="mysql is earlier than 0:4.1.22-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080768003" comment="mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080768006" comment="mysql-server is earlier than 0:4.1.22-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080768007" comment="mysql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080768004" comment="mysql-bench is earlier than 0:4.1.22-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080768005" comment="mysql-bench is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080768008" comment="mysql-devel is earlier than 0:4.1.22-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080768009" comment="mysql-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080780" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0780: coreutils security update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0780-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0780.html" />
          <reference source="CVE" ref_id="CVE-2008-1946" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1946.html" />
    
    <description>The coreutils package contains the core GNU utilities. It is the
combination of the old GNU fileutils, sh-utils, and textutils packages.

The coreutils packages were found to not use the pam_succeed_if Pluggable
Authentication Module (PAM) correctly in the configuration file for the
"su" command. Any local user could use this command to change to a locked
or expired user account if the target account's password was known to the
user running "su". These updated packages, correctly, only allow the root
user to switch to locked or expired accounts using "su". (CVE-2008-1946)

All users of coreutils are advised to upgrade to this updated package,
which resolve this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-24" />
        <updated date="2008-07-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1946.html">CVE-2008-1946</cve>
                <bugzilla href="http://bugzilla.redhat.com/446488" id="446488">CVE-2008-1946 /etc/pam.d/su is wrong in RHEL-4.6</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080780002" comment="coreutils is earlier than 0:5.2.1-31.8.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080780003" comment="coreutils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080789" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0789: dnsmasq security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0789-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0789.html" />
          <reference source="CVE" ref_id="CVE-2008-1447" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1447.html" />
    
    <description>Dnsmasq is lightweight DNS forwarder and DHCP server. It is designed to
provide DNS and, optionally, DHCP, to a small network.

The dnsmasq DNS resolver used a fixed source UDP port. This could have made
DNS spoofing attacks easier. dnsmasq has been updated to use random UDP
source ports, helping to make DNS spoofing attacks harder. (CVE-2008-1447)

All dnsmasq users are advised to upgrade to this updated package, that
upgrades dnsmasq to version 2.45, which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-11" />
        <updated date="2008-08-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1447.html">CVE-2008-1447</cve>
                <bugzilla href="http://bugzilla.redhat.com/449345" id="449345">CVE-2008-1447 implement source UDP port randomization (CERT VU#800113)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080789002" comment="dnsmasq is earlier than 0:2.45-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080789003" comment="dnsmasq is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080790" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0790: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0790-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0790.html" />
          <reference source="CVE" ref_id="CVE-2008-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3104.html" />
          <reference source="CVE" ref_id="CVE-2008-3106" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3106.html" />
          <reference source="CVE" ref_id="CVE-2008-3108" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3108.html" />
          <reference source="CVE" ref_id="CVE-2008-3111" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3111.html" />
          <reference source="CVE" ref_id="CVE-2008-3112" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3112.html" />
          <reference source="CVE" ref_id="CVE-2008-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3113.html" />
          <reference source="CVE" ref_id="CVE-2008-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3114.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

Multiple vulnerabilities with unsigned applets were reported. A remote
attacker could misuse an unsigned applet to connect to localhost services
running on the host running the applet. (CVE-2008-3104) 

A vulnerability in the XML processing API was found. A remote attacker who
caused malicious XML to be processed by an untrusted applet or application
was able to elevate permissions to access URLs on a remote host.
(CVE-2008-3106)

A buffer overflow vulnerability was found in the font processing code. This
allowed remote attackers to extend the permissions of an untrusted applet
or application, allowing it to read and/or write local files, as well as to
execute local applications accessible to the user running the untrusted
application. (CVE-2008-3108)

Several buffer overflow vulnerabilities in Java Web Start were reported.
These vulnerabilities allowed an untrusted Java Web Start application to
elevate its privileges, allowing it to read and/or write local files, as
well as to execute local applications accessible to the user running the
untrusted application. (CVE-2008-3111)

Two file processing vulnerabilities in Java Web Start were found. A remote
attacker, by means of an untrusted Java Web Start application, was able to
create or delete arbitrary files with the permissions of the user running
the untrusted application. (CVE-2008-3112, CVE-2008-3113)

A vulnerability in Java Web Start when processing untrusted applications
was reported. An attacker was able to acquire sensitive information, such
as the cache location. (CVE-2008-3114)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, that contain the IBM 1.5.0 SR8 Java release, which resolves
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-31" />
        <updated date="2008-07-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3104.html">CVE-2008-3104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3106.html">CVE-2008-3106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3108.html">CVE-2008-3108</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3111.html">CVE-2008-3111</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3112.html">CVE-2008-3112</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3113.html">CVE-2008-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3114.html">CVE-2008-3114</cve>
                <bugzilla href="http://bugzilla.redhat.com/452649" id="452649">CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454604" id="454604">CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454605" id="454605">CVE-2008-3111 Java Web Start Buffer overflow vulnerabilities (6557220)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454606" id="454606">CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454607" id="454607">CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454608" id="454608">CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location  (6704074)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790014" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790006" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210011" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790004" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790012" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790008" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790016" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210017" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080790010" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.8-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210009" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080812" version="504" class="patch">
      <metadata>
        <title>RHSA-2008:0812: RealPlayer security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0812-03" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0812.html" />
          <reference source="CVE" ref_id="CVE-2007-5400" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5400.html" />
    
    <description>RealPlayer is a media player that provides media playback locally and via
streaming.

RealPlayer 10.0.9 is vulnerable to a critical security flaw and should no
longer be used. A remote attacker could leverage this flaw to execute
arbitrary code as the user running RealPlayer. (CVE-2007-5400)

This issue is addressed in RealPlayer 11. Red Hat is unable to ship
RealPlayer 11 due to additional proprietary codecs included in that
version. Therefore, users who wish to continue to use RealPlayer should get
an update directly from www.real.com.

This update removes the RealPlayer 10.0.9 packages due to their known
security vulnerabilities.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-07-31" />
        <updated date="2008-09-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5400.html">CVE-2007-5400</cve>
                <bugzilla href="http://bugzilla.redhat.com/456855" id="456855">CVE-2007-5400 RealPlayer: SWF Frame Handling Buffer Overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080812002" comment="RealPlayer is earlier than 0:10.0.9-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080812003" comment="RealPlayer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080812004" comment="RealPlayer-uninstall is earlier than 0:10.0.9-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080812005" comment="RealPlayer-uninstall is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080815" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0815: yum-rhn-plugin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0815-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0815.html" />
          <reference source="CVE" ref_id="CVE-2008-3270" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3270.html" />
    
    <description>The yum-rhn-plugin provides support for yum to securely access a Red Hat
Network (RHN) server for software updates.

It was discovered that yum-rhn-plugin did not verify the SSL certificate
for all communication with a Red Hat Network server. An attacker able to
redirect the network communication between a victim and an RHN server could
use this flaw to provide malicious repository metadata. This metadata could
be used to block the victim from receiving specific security updates.
(CVE-2008-3270)

This flaw did not allow an attacker to install malicious packages. Package
signatures were verified and only packages signed with a trusted Red Hat
GPG key were installed.

Red Hat would like to thank Justin Cappos and Justin Samuel for discussing
various package update mechanism flaws which led to our discovery of this
issue.

Users of yum-rhn-plugin are advised to upgrade to this updated packages,
which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-14" />
        <updated date="2008-08-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3270.html">CVE-2008-3270</cve>
                <bugzilla href="http://bugzilla.redhat.com/457113" id="457113">CVE-2008-3270 yum-rhn-plugin: does not verify SSL certificate for all communication with RHN server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080815002" comment="yum-rhn-plugin is earlier than 0:0.5.3-12.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080815003" comment="yum-rhn-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080818" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0818: hplip security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0818-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0818.html" />
          <reference source="CVE" ref_id="CVE-2008-2940" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2940.html" />
          <reference source="CVE" ref_id="CVE-2008-2941" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2941.html" />
    
    <description>The hplip (Hewlett-Packard Linux Imaging and Printing) packages provide
drivers for Hewlett-Packard printers and multifunction peripherals.

A flaw was discovered in the hplip alert-mailing functionality. A local
attacker could elevate their privileges by using specially-crafted packets
to trigger alert mails, which are sent by the root account. (CVE-2008-2940)

A flaw was discovered in the hpssd message parser. By sending
specially-crafted packets, a local attacker could cause a denial of
service, stopping the hpssd process. (CVE-2008-2941)

Users of hplip should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-12" />
        <updated date="2008-08-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2940.html">CVE-2008-2940</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2941.html">CVE-2008-2941</cve>
                <bugzilla href="http://bugzilla.redhat.com/455235" id="455235">CVE-2008-2940 hpssd of hplip allows unprivileged user to trigger alert mail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457052" id="457052">CVE-2008-2941 hplip hpssd.py Denial-Of-Service parsing vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080818002" comment="hplip is earlier than 0:1.6.7-4.1.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080818003" comment="hplip is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080818006" comment="libsane-hpaio is earlier than 0:1.6.7-4.1.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080818007" comment="libsane-hpaio is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080818004" comment="hpijs is earlier than 0:1.6.7-4.1.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080818005" comment="hpijs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080835" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0835: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0835-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0835.html" />
          <reference source="CVE" ref_id="CVE-2008-3282" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3282.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.

A numeric truncation error was found in the OpenOffice.org memory
allocator. If a carefully crafted file was opened by a victim, an attacker
could use this flaw to crash OpenOffice.org or, possibly, execute arbitrary
code. (CVE-2008-3282)

All users of openoffice.org are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-27" />
        <updated date="2008-08-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3282.html">CVE-2008-3282</cve>
                <bugzilla href="http://bugzilla.redhat.com/458056" id="458056">CVE-2008-3282 openoffice.org: numeric truncation error in memory allocator (64bit)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835148" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175073" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835002" comment="openoffice.org is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835096" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175149" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835100" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175079" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835134" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175047" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835016" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175119" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835098" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175089" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835012" comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175125" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835058" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175031" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835074" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175101" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835130" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175095" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835040" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175043" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835060" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175017" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835070" comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537025" comment="openoffice.org-headless is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835026" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175107" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835146" comment="openoffice.org-base is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175051" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835048" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175097" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835102" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175077" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835154" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175009" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835118" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175103" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835068" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175131" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835056" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175067" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835018" comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175135" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835150" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175109" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835138" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175147" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835022" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175133" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835008" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175029" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835078" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175115" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835006" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175049" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835120" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175081" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835032" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175037" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835122" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175023" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835030" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175025" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835054" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175105" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835024" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175111" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835126" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175007" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835064" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175145" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835108" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175011" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835104" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175063" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835050" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175015" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835106" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175075" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835034" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175035" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835046" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175013" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835116" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175127" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835090" comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175113" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835014" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175069" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835144" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175143" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835072" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175039" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835114" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175027" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835110" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537155" comment="openoffice.org-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835112" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175129" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835086" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175137" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835092" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175093" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835052" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175123" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835020" comment="openoffice.org-math is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175045" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835080" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175057" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835082" comment="openoffice.org-core is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175085" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835036" comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175141" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835038" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835094" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175099" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835152" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175121" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835066" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175021" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835004" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175091" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835132" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175071" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835076" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175117" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835062" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537121" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835028" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175055" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835136" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175005" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835010" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175065" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835124" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175139" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835128" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175041" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835088" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175061" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835142" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175059" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835140" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175087" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835084" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175019" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835044" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175053" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080835042" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.2.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175083" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080836" version="505" class="patch">
      <metadata>
        <title>RHSA-2008:0836: libxml2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0836-04" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0836.html" />
          <reference source="CVE" ref_id="CVE-2008-3281" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3281.html" />
    
    <description>The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.

A denial of service flaw was found in the way libxml2 processes certain
content. If an application linked against libxml2 processes malformed XML
content, it could cause the application to stop responding. (CVE-2008-3281)

Red Hat would like to thank Andreas Solberg for responsibly disclosing this
issue.

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-21" />
        <updated date="2008-08-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3281.html">CVE-2008-3281</cve>
                <bugzilla href="http://bugzilla.redhat.com/458086" id="458086">CVE-2008-3281 libxml2 denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836002" comment="libxml2 is earlier than 0:2.6.26-2.1.2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032003" comment="libxml2 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836006" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032005" comment="libxml2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836004" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032007" comment="libxml2-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836009" comment="libxml2 is earlier than 0:2.5.10-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836013" comment="libxml2-devel is earlier than 0:2.5.10-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836011" comment="libxml2-python is earlier than 0:2.5.10-11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836016" comment="libxml2 is earlier than 0:2.6.16-12.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836017" comment="libxml2-devel is earlier than 0:2.6.16-12.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080836018" comment="libxml2-python is earlier than 0:2.6.16-12.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080839" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0839: postfix security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0839-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0839.html" />
          <reference source="CVE" ref_id="CVE-2008-2936" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2936.html" />
    
    <description>Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL),
and TLS.

A flaw was found in the way Postfix dereferences symbolic links. If a local
user has write access to a mail spool directory with no root mailbox, it
may be possible for them to append arbitrary data to files that root has
write permission to. (CVE-2008-2936)

Red Hat would like to thank Sebastian Krahmer for responsibly disclosing
this issue.

All users of postfix should upgrade to these updated packages, which
contain a backported patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-14" />
        <updated date="2008-08-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2936.html">CVE-2008-2936</cve>
                <bugzilla href="http://bugzilla.redhat.com/456314" id="456314">CVE-2008-2936 postfix privilege escalation flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080839004" comment="postfix-pflogsumm is earlier than 2:2.3.3-2.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080839005" comment="postfix-pflogsumm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080839002" comment="postfix is earlier than 2:2.3.3-2.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080839003" comment="postfix is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080839007" comment="postfix is earlier than 2:2.0.16-14.1.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080839008" comment="postfix is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080839011" comment="postfix-pflogsumm is earlier than 2:2.2.10-1.2.1.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080839012" comment="postfix-pflogsumm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080839010" comment="postfix is earlier than 2:2.2.10-1.2.1.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080839008" comment="postfix is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080847" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0847: libtiff security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0847-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0847.html" />
          <reference source="CVE" ref_id="CVE-2008-2327" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2327.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting this issue.

Additionally, these updated packages fix the following bug:

* the libtiff packages included manual pages for the sgi2tiff and tiffsv
commands, which are not included in these packages. These extraneous manual
pages were removed.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-28" />
        <updated date="2008-08-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2327.html">CVE-2008-2327</cve>
                <bugzilla href="http://bugzilla.redhat.com/458674" id="458674">CVE-2008-2327 libtiff: use of uninitialized memory in LZW decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460120" id="460120">[RHEL5] libtiff has unnecessary man pages.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080847002" comment="libtiff is earlier than 0:3.8.2-7.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080847003" comment="libtiff is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080847004" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080847005" comment="libtiff-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080848" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0848: libtiff security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0848-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0848.html" />
          <reference source="CVE" ref_id="CVE-2008-2327" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2327.html" />
          <reference source="CVE" ref_id="CVE-2006-2193" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2193.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting this issue.

A buffer overflow flaw was discovered in the tiff2pdf conversion program
distributed with libtiff. An attacker could create a TIFF file containing
UTF-8 characters that would, when converted to PDF format, cause tiff2pdf
to crash, or, possibly, execute arbitrary code. (CVE-2006-2193)

Additionally, these updated packages fix the following bug:

* the libtiff packages included manual pages for the sgi2tiff and tiffsv
commands, which are not included in these packages. These extraneous manual
pages were removed.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-28" />
        <updated date="2008-08-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2327.html">CVE-2008-2327</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2193.html">CVE-2006-2193</cve>
                <bugzilla href="http://bugzilla.redhat.com/194362" id="194362">CVE-2006-2193 tiff2pdf buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458674" id="458674">CVE-2008-2327 libtiff: use of uninitialized memory in LZW decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459404" id="459404">[RHEL4] libtiff has unnecessary man pages.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080848002" comment="libtiff is earlier than 0:3.6.1-12.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080848003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080848004" comment="libtiff-devel is earlier than 0:3.6.1-12.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080848005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080849" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0849: ipsec-tools security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0849-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0849.html" />
          <reference source="CVE" ref_id="CVE-2008-3651" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3651.html" />
          <reference source="CVE" ref_id="CVE-2008-3652" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3652.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the Linux kernel and includes racoon, an IKEv1 keying daemon.

Two denial of service flaws were found in the ipsec-tools racoon daemon. It
was possible for a remote attacker to cause the racoon daemon to consume
all available memory. (CVE-2008-3651, CVE-2008-3652)

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches that resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-26" />
        <updated date="2008-08-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3651.html">CVE-2008-3651</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3652.html">CVE-2008-3652</cve>
                <bugzilla href="http://bugzilla.redhat.com/456660" id="456660">CVE-2008-3651 ipsec-tools: racoon memory leak caused by invalid proposals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458846" id="458846">CVE-2008-3652 ipsec-tools: racoon orphaned ph1s memory leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080849002" comment="ipsec-tools is earlier than 0:0.6.5-9.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080849003" comment="ipsec-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080849005" comment="ipsec-tools is earlier than 0:0.2.5-0.7.rhel3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080849006" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080849008" comment="ipsec-tools is earlier than 0:0.3.3-7.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080849006" comment="ipsec-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080855" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0855: openssh security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0855-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0855.html" />
          <reference source="CVE" ref_id="CVE-2007-4752" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4752.html" />
          <reference source="CVE" ref_id="CVE-2008-3844" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3844.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure SHell) protocol implementation. 

Last week Red Hat detected an intrusion on certain of its computer systems
and took immediate action. While the investigation into the intrusion is
on-going, our initial focus  was to review and test the distribution
channel we use with our customers, Red Hat Network (RHN) and its associated
security measures. Based on these efforts, we remain highly confident that
our systems and processes prevented the intrusion from compromising RHN or
the content distributed via RHN and accordingly believe that customers who
keep their systems updated using Red Hat Network are not at risk.  We are
issuing this alert primarily for those who may obtain Red Hat binary
packages via channels other than those of official Red Hat subscribers.

In connection with the incident, the intruder was able to sign a small
number of OpenSSH packages relating only to Red Hat Enterprise Linux 4
(i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64
architecture only).  As a precautionary measure, we are releasing an
updated version of these packages, and have published a list of the
tampered packages and how to detect them at
http://www.redhat.com/security/data/openssh-blacklist.html

To reiterate, our processes and efforts to date indicate that packages
obtained by Red Hat Enterprise Linux subscribers via Red Hat Network are
not at risk.

These packages also fix a low severity flaw in the way ssh handles X11
cookies when creating X11 forwarding connections.  When ssh was unable to
create untrusted cookie, ssh used a trusted cookie instead, possibly
allowing the administrative user of a untrusted remote server, or untrusted
application run on the remote server, to gain unintended access to a users
local X server. (CVE-2007-4752)</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-22" />
        <updated date="2008-08-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4752.html">CVE-2007-4752</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3844.html">CVE-2008-3844</cve>
                <bugzilla href="http://bugzilla.redhat.com/280361" id="280361">CVE-2007-4752 openssh falls back to the trusted x11 cookie if generation of an untrusted cookie fails</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855002" comment="openssh is earlier than 0:4.3p2-26.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855003" comment="openssh is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855006" comment="openssh-clients is earlier than 0:4.3p2-26.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855007" comment="openssh-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855008" comment="openssh-server is earlier than 0:4.3p2-26.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855009" comment="openssh-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855004" comment="openssh-askpass is earlier than 0:4.3p2-26.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855005" comment="openssh-askpass is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855011" comment="openssh is earlier than 0:3.9p1-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855012" comment="openssh is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855017" comment="openssh-clients is earlier than 0:3.9p1-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855018" comment="openssh-clients is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855015" comment="openssh-askpass-gnome is earlier than 0:3.9p1-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855016" comment="openssh-askpass-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855019" comment="openssh-server is earlier than 0:3.9p1-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855020" comment="openssh-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080855013" comment="openssh-askpass is earlier than 0:3.9p1-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080855014" comment="openssh-askpass is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080863" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0863: libtiff security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0863-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0863.html" />
          <reference source="CVE" ref_id="CVE-2008-2327" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2327.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Multiple uses of uninitialized values were discovered in libtiff's
Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker could
create a carefully crafted LZW-encoded TIFF file that would cause an
application linked with libtiff to crash or, possibly, execute arbitrary
code. (CVE-2008-2327)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting this issue.

All libtiff users are advised to upgrade to these updated packages, which
contain backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-08-28" />
        <updated date="2008-08-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2327.html">CVE-2008-2327</cve>
                <bugzilla href="http://bugzilla.redhat.com/458674" id="458674">CVE-2008-2327 libtiff: use of uninitialized memory in LZW decoder</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080863002" comment="libtiff is earlier than 0:3.5.7-31.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080848003" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080863004" comment="libtiff-devel is earlier than 0:3.5.7-31.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080848005" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080879" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0879: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0879-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0879.html" />
          <reference source="CVE" ref_id="CVE-2008-3837" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3837.html" />
          <reference source="CVE" ref_id="CVE-2008-4058" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4058.html" />
          <reference source="CVE" ref_id="CVE-2008-4060" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4060.html" />
          <reference source="CVE" ref_id="CVE-2008-4061" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4061.html" />
          <reference source="CVE" ref_id="CVE-2008-4062" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4062.html" />
          <reference source="CVE" ref_id="CVE-2008-4063" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4063.html" />
          <reference source="CVE" ref_id="CVE-2008-4064" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4064.html" />
          <reference source="CVE" ref_id="CVE-2008-4065" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4065.html" />
          <reference source="CVE" ref_id="CVE-2008-4067" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4067.html" />
          <reference source="CVE" ref_id="CVE-2008-4068" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4068.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-4058, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,
CVE-2008-4063, CVE-2008-4064)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-4067,
CVE-2008-4068)

A flaw was found in the way Firefox handles mouse click events. A web page
containing specially crafted JavaScript code could move the content window
while a mouse-button was pressed, causing any item under the pointer to be
dragged. This could, potentially, cause the user to perform an unsafe
drag-and-drop action. (CVE-2008-3837)

A flaw was found in Firefox that caused certain characters to be stripped
from JavaScript code. This flaw could allow malicious JavaScript to bypass
or evade script filters. (CVE-2008-4065)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.2. You can find a link to the Mozilla
advisories in the References section.

All firefox users should upgrade to this updated package, which contains
backported patches that correct these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-09-23" />
        <updated date="2008-09-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3837.html">CVE-2008-3837</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4058.html">CVE-2008-4058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4060.html">CVE-2008-4060</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4061.html">CVE-2008-4061</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4062.html">CVE-2008-4062</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4063.html">CVE-2008-4063</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4064.html">CVE-2008-4064</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4065.html">CVE-2008-4065</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4067.html">CVE-2008-4067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4068.html">CVE-2008-4068</cve>
                <bugzilla href="http://bugzilla.redhat.com/463189" id="463189">CVE-2008-3837 mozilla: Forced mouse drag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463190" id="463190">CVE-2008-4058 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463198" id="463198">CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463199" id="463199">CVE-2008-4061 Mozilla layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463201" id="463201">CVE-2008-4062 Mozilla crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463203" id="463203">CVE-2008-4063 Mozilla crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463204" id="463204">CVE-2008-4064 Mozilla crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463234" id="463234">CVE-2008-4065 Mozilla BOM characters stripped from JavaScript before execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463246" id="463246">CVE-2008-4067 Mozilla resource: traversal vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463248" id="463248">CVE-2008-4068 Mozilla local HTML file recource: bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879002" comment="yelp is earlier than 0:2.16.0-21.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569009" comment="yelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879004" comment="devhelp is earlier than 0:0.12-19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569011" comment="devhelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879006" comment="devhelp-devel is earlier than 0:0.12-19.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569013" comment="devhelp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879008" comment="nss is earlier than 0:3.12.1.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879009" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879014" comment="nss-tools is earlier than 0:3.12.1.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879015" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879012" comment="nss-devel is earlier than 0:3.12.1.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879013" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879010" comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879011" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879018" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.2-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569007" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879016" comment="xulrunner is earlier than 0:1.9.0.2-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879020" comment="xulrunner-devel is earlier than 0:1.9.0.2-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080879022" comment="firefox is earlier than 0:3.0.2-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879025" comment="firefox is earlier than 0:3.0.2-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080882" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0882: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0882-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0882.html" />
          <reference source="CVE" ref_id="CVE-2008-0016" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0016.html" />
          <reference source="CVE" ref_id="CVE-2008-3835" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3835.html" />
          <reference source="CVE" ref_id="CVE-2008-3837" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3837.html" />
          <reference source="CVE" ref_id="CVE-2008-4058" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4058.html" />
          <reference source="CVE" ref_id="CVE-2008-4059" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4059.html" />
          <reference source="CVE" ref_id="CVE-2008-4060" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4060.html" />
          <reference source="CVE" ref_id="CVE-2008-4061" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4061.html" />
          <reference source="CVE" ref_id="CVE-2008-4062" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4062.html" />
          <reference source="CVE" ref_id="CVE-2008-4065" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4065.html" />
          <reference source="CVE" ref_id="CVE-2008-4066" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4066.html" />
          <reference source="CVE" ref_id="CVE-2008-4067" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4067.html" />
          <reference source="CVE" ref_id="CVE-2008-4068" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4068.html" />
          <reference source="CVE" ref_id="CVE-2008-4069" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4069.html" />
    
    <description>SeaMonkey is an open source Web browser, advanced email and newsgroup
client, IRC chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061,
CVE-2008-4062)

Several flaws were found in the way malformed web content was displayed. A
web page containing specially crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-3835,
CVE-2008-4067, CVE-2008-4068, CVE-2008-4069)

A flaw was found in the way SeaMonkey handles mouse click events. A web page
containing specially crafted JavaScript code could move the content window
while a mouse-button was pressed, causing any item under the pointer to be
dragged. This could, potentially, cause the user to perform an unsafe
drag-and-drop action. (CVE-2008-3837)

A flaw was found in SeaMonkey that caused certain characters to be stripped
from JavaScript code. This flaw could allow malicious JavaScript to bypass
or evade script filters. (CVE-2008-4065, CVE-2008-4066)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-09-23" />
        <updated date="2008-09-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0016.html">CVE-2008-0016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3835.html">CVE-2008-3835</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3837.html">CVE-2008-3837</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4058.html">CVE-2008-4058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4059.html">CVE-2008-4059</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4060.html">CVE-2008-4060</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4061.html">CVE-2008-4061</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4062.html">CVE-2008-4062</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4065.html">CVE-2008-4065</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4066.html">CVE-2008-4066</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4067.html">CVE-2008-4067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4068.html">CVE-2008-4068</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4069.html">CVE-2008-4069</cve>
                <bugzilla href="http://bugzilla.redhat.com/463181" id="463181">CVE-2008-0016 Mozilla UTF-8 stack buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463182" id="463182">CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463189" id="463189">CVE-2008-3837 mozilla: Forced mouse drag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463190" id="463190">CVE-2008-4058 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463192" id="463192">CVE-2008-4059 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463198" id="463198">CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463199" id="463199">CVE-2008-4061 Mozilla layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463201" id="463201">CVE-2008-4062 Mozilla crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463234" id="463234">CVE-2008-4065 Mozilla BOM characters stripped from JavaScript before execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463243" id="463243">CVE-2008-4066 Mozilla low surrogates stripped from JavaScript before execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463246" id="463246">CVE-2008-4067 Mozilla resource: traversal vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463248" id="463248">CVE-2008-4068 Mozilla local HTML file recource: bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463251" id="463251">CVE-2008-4069 Mozilla XBM decoder information disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882014" comment="seamonkey-nspr is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882012" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882016" comment="seamonkey-mail is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882002" comment="seamonkey is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882018" comment="seamonkey-devel is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882020" comment="seamonkey-chat is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882006" comment="seamonkey-nss is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.24.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882023" comment="devhelp is earlier than 0:0.10-0.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080599034" comment="devhelp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882025" comment="devhelp-devel is earlier than 0:0.10-0.10.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080599036" comment="devhelp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882032" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882029" comment="seamonkey-mail is earlier than 0:1.0.9-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882027" comment="seamonkey is earlier than 0:1.0.9-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882030" comment="seamonkey-devel is earlier than 0:1.0.9-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882031" comment="seamonkey-chat is earlier than 0:1.0.9-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080882028" comment="seamonkey-js-debugger is earlier than 0:1.0.9-26.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080884" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0884: libxml2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0884-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0884.html" />
          <reference source="CVE" ref_id="CVE-2008-3529" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3529.html" />
    
    <description>The libxml2 packages provide a library that allows you to manipulate XML
files. It includes support to read, modify, and write XML and HTML files.

A heap-based buffer overflow flaw was found in the way libxml2 handled long
XML entity names. If an application linked against libxml2 processed
untrusted malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-3529)

All users of libxml2 are advised to upgrade to these updated packages,
which contain a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-09-11" />
        <updated date="2008-09-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3529.html">CVE-2008-3529</cve>
                <bugzilla href="http://bugzilla.redhat.com/461015" id="461015">CVE-2008-3529 libxml2: long entity name heap buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884002" comment="libxml2 is earlier than 0:2.6.26-2.1.2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032003" comment="libxml2 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884004" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032005" comment="libxml2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884006" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032007" comment="libxml2-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884009" comment="libxml2 is earlier than 0:2.5.10-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884011" comment="libxml2-devel is earlier than 0:2.5.10-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884013" comment="libxml2-python is earlier than 0:2.5.10-13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884016" comment="libxml2 is earlier than 0:2.6.16-12.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884017" comment="libxml2-devel is earlier than 0:2.6.16-12.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080884018" comment="libxml2-python is earlier than 0:2.6.16-12.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080885" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0885: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0885-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0885.html" />
          <reference source="CVE" ref_id="CVE-2008-2931" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2931.html" />
          <reference source="CVE" ref_id="CVE-2008-3275" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3275.html" />
          <reference source="CVE" ref_id="CVE-2007-6417" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6417.html" />
          <reference source="CVE" ref_id="CVE-2007-6716" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6716.html" />
          <reference source="CVE" ref_id="CVE-2008-3272" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3272.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a missing capability check was found in the Linux kernel do_change_type
routine. This could allow a local unprivileged user to gain privileged
access or cause a denial of service. (CVE-2008-2931, Important)

* a flaw was found in the Linux kernel Direct-IO implementation. This could
allow a local unprivileged user to cause a denial of service.
(CVE-2007-6716, Important)

* Tobias Klein reported a missing check in the Linux kernel Open Sound
System (OSS) implementation. This deficiency could lead to a possible
information leak. (CVE-2008-3272, Moderate)

* a deficiency was found in the Linux kernel virtual filesystem (VFS)
implementation. This could allow a local unprivileged user to attempt file
creation within deleted directories, possibly causing a denial of service.
(CVE-2008-3275, Moderate)

* a flaw was found in the Linux kernel tmpfs implementation. This could
allow a local unprivileged user to read sensitive information from the
kernel. (CVE-2007-6417, Moderate)

Bug fixes:

* when copying a small IPoIB packet from the original skb it was received
in to a new, smaller skb, all fields in the new skb were not initialized.
This may have caused a kernel oops.

* previously, data may have been written beyond the end of an array,
causing memory corruption on certain systems, resulting in hypervisor
crashes during context switching.

* a kernel crash may have occurred on heavily-used Samba servers after 24
to 48 hours of use.

* under heavy memory pressure, pages may have been swapped out from under
the SGI Altix XPMEM driver, causing silent data corruption in the kernel.

* the ixgbe driver is untested, but support was advertised for the Intel
82598 network card. If this card was present when the ixgbe driver was
loaded, a NULL pointer dereference and a panic occurred.

* on certain systems, if multiple InfiniBand queue pairs simultaneously
fell into an error state, an overrun may have occurred, stopping traffic.

* with bridging, when forward delay was set to zero, setting an interface
to the forwarding state was delayed by one or possibly two timers,
depending on whether STP was enabled. This may have caused long delays in
moving an interface to the forwarding state. This issue caused packet loss
when migrating virtual machines, preventing them from being migrated
without interrupting applications.

* on certain multinode systems, IPMI device nodes were created in reverse
order of where they physically resided.

* process hangs may have occurred while accessing application data files
via asynchronous direct I/O system calls.

* on systems with heavy lock traffic, a possible deadlock may have caused
anything requiring locks over NFS to stop, or be very slow. Errors such as
"lockd: server [IP] not responding, timed out" were logged on client
systems.

* unexpected removals of USB devices may have caused a NULL pointer
dereference in kobject_get_path.

* on Itanium-based systems, repeatedly creating and destroying Windows
guests may have caused Dom0 to crash, due to the "XENMEM_add_to_physmap"
hypercall, used by para-virtualized drivers on HVM, being SMP-unsafe.

* when using an MD software RAID, crashes may have occurred when devices
were removed or changed while being iterated through. Correct locking is
now used.

* break requests had no effect when using "Serial Over Lan" with the Intel
82571 network card. This issue may have caused log in problems.

* on Itanium-based systems, module_free() referred the first parameter
before checking it was valid. This may have caused a kernel panic when
exiting SystemTap.

Red Hat Enterprise Linux 5 users are advised to upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-09-24" />
        <updated date="2008-09-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2931.html">CVE-2008-2931</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3275.html">CVE-2008-3275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6417.html">CVE-2007-6417</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6716.html">CVE-2007-6716</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3272.html">CVE-2008-3272</cve>
                <bugzilla href="http://bugzilla.redhat.com/426081" id="426081">CVE-2007-6417 tmpfs: restore missing clear_highpage (kernels from 2.6.11 up)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447913" id="447913">LTC43854-trap 700 Program check on uli05, pc: c000000000323910: .skb_under_panic+0x50/0x68 [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454388" id="454388">CVE-2008-2931 kernel: missing check before setting mount propagation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455768" id="455768">Guest OS install causes host machine to crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456235" id="456235">[RHEL5] Kernel panic triggered by smbd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456946" id="456946">Silent memory corruption with xpmem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457484" id="457484">ixgbe panics system when installing RHEL 5.2 with 82598AT (copper 10 gig) adapter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457858" id="457858">CVE-2008-3275 Linux kernel local filesystem DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457995" id="457995">CVE-2008-3272 kernel snd_seq_oss_synth_make_info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458779" id="458779">LTC44570-Event Queue overflow on eHCA adapters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458783" id="458783">lost packets when live migrating</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459071" id="459071">LTC41679-IPMI device nodes created in reverse order on multinode systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459082" id="459082">process hangs in async direct IO / possible race between dio_bio_end_aio() and dio_await_one() ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459083" id="459083">deadlock when lockd tries to take f_sema that it already has</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459776" id="459776">[Stratus 5.2.z bug] kernel NULL pointer dereference in kobject_get_path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459780" id="459780">[IA64] Fix SMP-unsafe with XENMEM_add_to_physmap on HVM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460128" id="460128">[NEC/Stratus 5.2.z bug] various crashes in md - rdev removed in the middle of ITERATE_RDEV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460509" id="460509">SysRq handling issue in serial driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460639" id="460639">kprobes remove causing kernel panic on ia64 with 2.6.18-92.1.10.el5 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461082" id="461082">CVE-2007-6716 kernel: dio: zero struct dio with kzalloc instead of manually</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885004" comment="kernel-headers is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885002" comment="kernel is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885024" comment="kernel-doc is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885020" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885008" comment="kernel-devel is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885014" comment="kernel-debug is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885018" comment="kernel-kdump is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885010" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885012" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885022" comment="kernel-PAE is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885016" comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080885006" comment="kernel-xen is earlier than 0:2.6.18-92.1.13.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080890" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0890: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0890-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0890.html" />
          <reference source="CVE" ref_id="CVE-2008-1070" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1070.html" />
          <reference source="CVE" ref_id="CVE-2008-1071" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1071.html" />
          <reference source="CVE" ref_id="CVE-2008-1072" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1072.html" />
          <reference source="CVE" ref_id="CVE-2008-1561" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1561.html" />
          <reference source="CVE" ref_id="CVE-2008-1562" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1562.html" />
          <reference source="CVE" ref_id="CVE-2008-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1563.html" />
          <reference source="CVE" ref_id="CVE-2008-3137" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3137.html" />
          <reference source="CVE" ref_id="CVE-2008-3138" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3138.html" />
          <reference source="CVE" ref_id="CVE-2008-3141" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3141.html" />
          <reference source="CVE" ref_id="CVE-2008-3145" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3145.html" />
          <reference source="CVE" ref_id="CVE-2008-3146" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3146.html" />
          <reference source="CVE" ref_id="CVE-2008-3932" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3932.html" />
          <reference source="CVE" ref_id="CVE-2008-3933" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3933.html" />
          <reference source="CVE" ref_id="CVE-2008-3934" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3934.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network, it could crash or, possibly, execute
arbitrary code as the user running Wireshark. (CVE-2008-3146)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malformed dump file. (CVE-2008-1070, CVE-2008-1071, CVE-2008-1072,
CVE-2008-1561, CVE-2008-1562, CVE-2008-1563, CVE-2008-3137, CVE-2008-3138,
CVE-2008-3141, CVE-2008-3145, CVE-2008-3932, CVE-2008-3933, CVE-2008-3934)

Additionally, this update changes the default Pluggable Authentication
Modules (PAM) configuration to always prompt for the root password before
each start of Wireshark. This avoids unintentionally running Wireshark with
root privileges.

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.3, and resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-01" />
        <updated date="2008-10-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1070.html">CVE-2008-1070</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1071.html">CVE-2008-1071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1072.html">CVE-2008-1072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1561.html">CVE-2008-1561</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1562.html">CVE-2008-1562</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1563.html">CVE-2008-1563</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3137.html">CVE-2008-3137</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3138.html">CVE-2008-3138</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3141.html">CVE-2008-3141</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3145.html">CVE-2008-3145</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3146.html">CVE-2008-3146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3932.html">CVE-2008-3932</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3933.html">CVE-2008-3933</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3934.html">CVE-2008-3934</cve>
                <bugzilla href="http://bugzilla.redhat.com/435481" id="435481">CVE-2008-1070 wireshark: SCTP dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435482" id="435482">CVE-2008-1071 wireshark: SNMP dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435483" id="435483">CVE-2008-1072 wireshark: TFTP dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439943" id="439943">CVE-2008-1563 wireshark: crash in SCCP dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440014" id="440014">CVE-2008-1561 wireshark: crash in X.509sat and Roofnet dissectors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440015" id="440015">CVE-2008-1562 wireshark: crash in LDAP dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448584" id="448584">Don't automatically use stored privileges</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454970" id="454970">CVE-2008-3137 wireshark: crash in the GSM SMS dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454971" id="454971">CVE-2008-3138 wireshark: unexpected exit in the PANA and KISMET dissectors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454975" id="454975">CVE-2008-3141 wireshark: memory disclosure in the RMI dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454984" id="454984">CVE-2008-3145 wireshark: crash in the packet reassembling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461242" id="461242">CVE-2008-3146 wireshark: multiple buffer overflows in NCP dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461243" id="461243">CVE-2008-3932 wireshark: infinite loop in the NCP dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461244" id="461244">CVE-2008-3933 wireshark: crash triggered by zlib-compressed packet data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461245" id="461245">CVE-2008-3934 wireshark: crash via crafted Tektronix .rf5 file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080890002" comment="wireshark is earlier than 0:1.0.3-4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080890004" comment="wireshark-gnome is earlier than 0:1.0.3-4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080890007" comment="wireshark is earlier than 0:1.0.3-EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058012" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080890009" comment="wireshark-gnome is earlier than 0:1.0.3-EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058014" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080890012" comment="wireshark is earlier than 0:1.0.3-3.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058012" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080890013" comment="wireshark-gnome is earlier than 0:1.0.3-3.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080058014" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080891" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0891: java-1.5.0-ibm security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0891-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0891.html" />
          <reference source="CVE" ref_id="CVE-2008-3103" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3103.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

A flaw was found in the Java Management Extensions (JMX) management agent.
When local monitoring is enabled, remote attackers could use this flaw to
perform illegal operations. (CVE-2008-3103) 

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages containing the IBM 1.5.0 SR8a Java release, which resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-24" />
        <updated date="2008-10-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3103.html">CVE-2008-3103</cve>
                <bugzilla href="http://bugzilla.redhat.com/452659" id="452659">CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891014" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891016" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210011" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891012" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891010" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210013" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891006" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891004" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210017" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080891008" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.8-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080210009" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080892" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0892: xen security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0892-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0892.html" />
          <reference source="CVE" ref_id="CVE-2008-1945" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1945.html" />
          <reference source="CVE" ref_id="CVE-2008-1952" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1952.html" />
    
    <description>The xen packages contain tools for managing the virtual machine monitor in
Red Hat Virtualization.

It was discovered that the hypervisor's para-virtualized framebuffer (PVFB)
backend failed to validate the frontend's framebuffer description properly.
This could allow a privileged user in the unprivileged domain (DomU) to
cause a denial of service, or, possibly, elevate privileges to the
privileged domain (Dom0). (CVE-2008-1952)

A flaw was found in the QEMU block format auto-detection, when running
fully-virtualized guests and using Qemu images written on removable media
(USB storage, 3.5" disks). Privileged users of such fully-virtualized
guests (DomU), with a raw-formatted disk image, were able to write a header
to that disk image describing another format. This could allow such guests
to read arbitrary files in their hypervisor's host (Dom0). (CVE-2008-1945)

Additionally, the following bug is addressed in this update:

* The qcow-create command terminated when invoked due to glibc bounds
checking on the realpath() function.

Users of xen are advised to upgrade to these updated packages, which
resolve these security issues and fix this bug.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-01" />
        <updated date="2008-10-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1945.html">CVE-2008-1945</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1952.html">CVE-2008-1952</cve>
                <bugzilla href="http://bugzilla.redhat.com/445844" id="445844">CVE-2008-1945 qemu/kvm/xen: add image format options for USB storage and removable media</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447759" id="447759">CVE-2008-1952 qemu/xen/kvm: ioemu: Fix PVFB backend to limit frame buffer size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454651" id="454651">xen: buffer overflow detected: qcow-create terminated</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080892002" comment="xen is earlier than 0:3.0.3-64.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080194003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080892004" comment="xen-libs is earlier than 0:3.0.3-64.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080194007" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080892006" comment="xen-devel is earlier than 0:3.0.3-64.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080194005" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080893" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0893: bzip2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0893-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0893.html" />
          <reference source="CVE" ref_id="CVE-2008-1372" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1372.html" />
    
    <description>Bzip2 is a freely available, high-quality data compressor. It provides both
stand-alone compression and decompression utilities, as well as a shared
library for use with other programs.

A buffer over-read flaw was discovered in the bzip2 decompression routine.
This issue could cause an application linked against the libbz2 library to
crash when decompressing malformed archives. (CVE-2008-1372)

Users of bzip2 should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-09-16" />
        <updated date="2008-09-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1372.html">CVE-2008-1372</cve>
                <bugzilla href="http://bugzilla.redhat.com/438118" id="438118">CVE-2008-1372 bzip2: crash on malformed archive file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893004" comment="bzip2-devel is earlier than 0:1.0.3-4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893005" comment="bzip2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893006" comment="bzip2-libs is earlier than 0:1.0.3-4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893007" comment="bzip2-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893002" comment="bzip2 is earlier than 0:1.0.3-4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893003" comment="bzip2 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893013" comment="bzip2-devel is earlier than 0:1.0.2-12.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893014" comment="bzip2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893011" comment="bzip2-libs is earlier than 0:1.0.2-12.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893012" comment="bzip2-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893009" comment="bzip2 is earlier than 0:1.0.2-12.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893010" comment="bzip2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893018" comment="bzip2-devel is earlier than 0:1.0.2-14.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893014" comment="bzip2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893017" comment="bzip2-libs is earlier than 0:1.0.2-14.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893012" comment="bzip2-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080893016" comment="bzip2 is earlier than 0:1.0.2-14.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080893010" comment="bzip2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080896" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0896: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0896-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0896.html" />
          <reference source="CVE" ref_id="CVE-2008-3443" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3443.html" />
          <reference source="CVE" ref_id="CVE-2008-3655" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3655.html" />
          <reference source="CVE" ref_id="CVE-2008-3905" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3905.html" />
    
    <description>Ruby is an interpreted scripting language for quick and easy
object-oriented programming.

The Ruby DNS resolver library, resolv.rb, used predictable transaction IDs
and a fixed source port when sending DNS requests. A remote attacker could
use this flaw to spoof a malicious reply to a DNS query. (CVE-2008-3905)

A number of flaws were found in the safe-level restrictions in Ruby. It
was possible for an attacker to create a carefully crafted malicious script
that can allow the bypass of certain safe-level restrictions. (CVE-2008-3655)

A denial of service flaw was found in Ruby's regular expression engine. If
a Ruby script tried to process a large amount of data via a regular
expression, it could cause Ruby to enter an infinite-loop and crash.
(CVE-2008-3443)

Users of ruby should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-21" />
        <updated date="2008-10-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3443.html">CVE-2008-3443</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3655.html">CVE-2008-3655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3905.html">CVE-2008-3905</cve>
                <bugzilla href="http://bugzilla.redhat.com/458948" id="458948">CVE-2008-3655 ruby: multiple insufficient safe mode restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459266" id="459266">CVE-2008-3443 ruby: Memory allocation failure in Ruby regex engine (remotely exploitable DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461495" id="461495">CVE-2008-3905 ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896014" comment="ruby-docs is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561028" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896008" comment="irb is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561032" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896006" comment="ruby-mode is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561026" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896012" comment="ruby-tcltk is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561030" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896004" comment="ruby-libs is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561034" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896002" comment="ruby is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561022" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080896010" comment="ruby-devel is earlier than 0:1.6.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561024" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080897" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0897: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0897-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0897.html" />
          <reference source="CVE" ref_id="CVE-2008-3443" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3443.html" />
          <reference source="CVE" ref_id="CVE-2008-3655" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3655.html" />
          <reference source="CVE" ref_id="CVE-2008-3656" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3656.html" />
          <reference source="CVE" ref_id="CVE-2008-3657" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3657.html" />
          <reference source="CVE" ref_id="CVE-2008-3790" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3790.html" />
          <reference source="CVE" ref_id="CVE-2008-3905" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3905.html" />
          <reference source="CVE" ref_id="CVE-2008-1145" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1145.html" />
    
    <description>Ruby is an interpreted scripting language for quick and easy
object-oriented programming.

The Ruby DNS resolver library, resolv.rb, used predictable transaction IDs
and a fixed source port when sending DNS requests. A remote attacker could
use this flaw to spoof a malicious reply to a DNS query. (CVE-2008-3905)

Ruby's XML document parsing module (REXML) was prone to a denial of service
attack via XML documents with large XML entity definitions recursion. A
specially-crafted XML file could cause a Ruby application using the REXML
module to use an excessive amount of CPU and memory. (CVE-2008-3790)

An insufficient "taintness" check flaw was discovered in Ruby's DL module,
which provides direct access to the C language functions. An attacker could
use this flaw to bypass intended safe-level restrictions by calling
external C functions with the arguments from an untrusted tainted inputs.
(CVE-2008-3657)

A denial of service flaw was discovered in WEBrick, Ruby's HTTP server
toolkit. A remote attacker could send a specially-crafted HTTP request to a
WEBrick server that would cause the server to use an excessive amount of
CPU time. (CVE-2008-3656)

A number of flaws were found in the safe-level restrictions in Ruby. It
was possible for an attacker to create a carefully crafted malicious script
that can allow the bypass of certain safe-level restrictions. (CVE-2008-3655)

A denial of service flaw was found in Ruby's regular expression engine. If
a Ruby script tried to process a large amount of data via a regular
expression, it could cause Ruby to enter an infinite-loop and crash.
(CVE-2008-3443)

Users of ruby should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-21" />
        <updated date="2008-10-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3443.html">CVE-2008-3443</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3655.html">CVE-2008-3655</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3656.html">CVE-2008-3656</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3657.html">CVE-2008-3657</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3790.html">CVE-2008-3790</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3905.html">CVE-2008-3905</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1145.html">CVE-2008-1145</cve>
                <bugzilla href="http://bugzilla.redhat.com/458948" id="458948">CVE-2008-3655 ruby: multiple insufficient safe mode restrictions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458953" id="458953">CVE-2008-3656 ruby: WEBrick DoS vulnerability (CPU consumption)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458966" id="458966">CVE-2008-3657 ruby: missing "taintness" checks in dl module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459266" id="459266">CVE-2008-3443 ruby: Memory allocation failure in Ruby regex engine (remotely exploitable DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460134" id="460134">CVE-2008-3790 ruby: DoS vulnerability in the REXML module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461495" id="461495">CVE-2008-3905 ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897014" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561015" comment="ruby-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897006" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561005" comment="ruby-ri is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897012" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561009" comment="ruby-mode is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897016" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561013" comment="ruby-tcltk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897004" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561019" comment="ruby-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897008" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561007" comment="ruby-irb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897010" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561011" comment="ruby-rdoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897002" comment="ruby is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561003" comment="ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897018" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561017" comment="ruby-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897033" comment="irb is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561032" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897025" comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561028" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897031" comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561026" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897029" comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561034" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897023" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561030" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897021" comment="ruby is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561022" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080897027" comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561024" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080906" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0906: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0906-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0906.html" />
          <reference source="CVE" ref_id="CVE-2008-3103" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3103.html" />
          <reference source="CVE" ref_id="CVE-2008-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3104.html" />
          <reference source="CVE" ref_id="CVE-2008-3105" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3105.html" />
          <reference source="CVE" ref_id="CVE-2008-3106" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3106.html" />
          <reference source="CVE" ref_id="CVE-2008-3109" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3109.html" />
          <reference source="CVE" ref_id="CVE-2008-3110" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3110.html" />
          <reference source="CVE" ref_id="CVE-2008-3112" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3112.html" />
          <reference source="CVE" ref_id="CVE-2008-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3114.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

A flaw was found in the Java Management Extensions (JMX) management agent.
When local monitoring is enabled, remote attackers could use this flaw to
perform illegal operations. (CVE-2008-3103) 

Several flaws involving the handling of unsigned applets were found. A
remote attacker could misuse an unsigned applet in order to connect to
services on the host running the applet. (CVE-2008-3104)

Several flaws in the Java API for XML Web Services (JAX-WS) client and the
JAX-WS service implementation were found. A remote attacker who could cause
malicious XML to be processed by an application could access URLs, or cause
a denial of service. (CVE-2008-3105, CVE-2008-3106)

Several flaws within the Java Runtime Environment (JRE) scripting support
were found. A remote attacker could grant an untrusted applet extended
privileges, such as reading and writing local files, executing
local programs, or querying the sensitive data of other applets.
(CVE-2008-3109, CVE-2008-3110)

A flaw in Java Web Start was found. Using an untrusted Java Web
Start application, a remote attacker could create or delete arbitrary
files with the permissions of the user running the untrusted application.
(CVE-2008-3112)

A flaw in Java Web Start when processing untrusted applications was found.
An attacker could use this flaw to acquire sensitive information, such as
the location of the cache. (CVE-2008-3114)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR2 Java release, which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-24" />
        <updated date="2008-10-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3103.html">CVE-2008-3103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3104.html">CVE-2008-3104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3105.html">CVE-2008-3105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3106.html">CVE-2008-3106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3109.html">CVE-2008-3109</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3110.html">CVE-2008-3110</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3112.html">CVE-2008-3112</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3114.html">CVE-2008-3114</cve>
                <bugzilla href="http://bugzilla.redhat.com/452649" id="452649">CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452659" id="452659">CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454603" id="454603">CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454606" id="454606">CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454608" id="454608">CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location  (6704074)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906006" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267015" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906014" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267017" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906010" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267009" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906016" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267005" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906004" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267013" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906012" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267007" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080906008" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.2-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080267011" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080907" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0907: pam_krb5 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0907-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0907.html" />
          <reference source="CVE" ref_id="CVE-2008-3825" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3825.html" />
    
    <description>The pam_krb5 module allows Pluggable Authentication Modules (PAM) aware
applications to use Kerberos to verify user identities by obtaining user
credentials at log in time.

A flaw was found in the pam_krb5 "existing_ticket" configuration option. If
a system is configured to use an existing credential cache via the
"existing_ticket" option, it may be possible for a local user to gain
elevated privileges by using a different, local user's credential cache.
(CVE-2008-3825)

Red Hat would like to thank Stéphane Bertin for responsibly disclosing this
issue.

Users of pam_krb5 should upgrade to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-02" />
        <updated date="2008-10-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3825.html">CVE-2008-3825</cve>
                <bugzilla href="http://bugzilla.redhat.com/461960" id="461960">CVE-2008-3825 pam_krb5 existing_ticket permission flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080907002" comment="pam_krb5 is earlier than 0:2.2.14-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080907003" comment="pam_krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080908" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0908: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0908-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0908.html" />
          <reference source="CVE" ref_id="CVE-2008-0016" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0016.html" />
          <reference source="CVE" ref_id="CVE-2008-3835" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3835.html" />
          <reference source="CVE" ref_id="CVE-2008-4058" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4058.html" />
          <reference source="CVE" ref_id="CVE-2008-4059" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4059.html" />
          <reference source="CVE" ref_id="CVE-2008-4060" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4060.html" />
          <reference source="CVE" ref_id="CVE-2008-4061" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4061.html" />
          <reference source="CVE" ref_id="CVE-2008-4062" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4062.html" />
          <reference source="CVE" ref_id="CVE-2008-4065" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4065.html" />
          <reference source="CVE" ref_id="CVE-2008-4066" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4066.html" />
          <reference source="CVE" ref_id="CVE-2008-4067" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4067.html" />
          <reference source="CVE" ref_id="CVE-2008-4068" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4068.html" />
          <reference source="CVE" ref_id="CVE-2008-4070" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4070.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060,
CVE-2008-4061, CVE-2008-4062)

Several flaws were found in the way malformed HTML mail content was
displayed. An HTML mail message containing specially crafted content could
potentially trick a Thunderbird user into surrendering sensitive
information. (CVE-2008-3835, CVE-2008-4067, CVE-2008-4068)

A flaw was found in Thunderbird that caused certain characters to be
stripped from JavaScript code. This flaw could allow malicious JavaScript
to bypass or evade script filters. (CVE-2008-4065, CVE-2008-4066)

Note: JavaScript support is disabled by default in Thunderbird; the above
issue is not exploitable unless JavaScript is enabled.

A heap based buffer overflow flaw was found in the handling of cancelled
newsgroup messages. If the user cancels a specially crafted newsgroup
message it could cause Thunderbird to crash or, potentially, execute
arbitrary code as the user running Thunderbird. (CVE-2008-4070)

All Thunderbird users should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-01" />
        <updated date="2008-10-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0016.html">CVE-2008-0016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3835.html">CVE-2008-3835</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4058.html">CVE-2008-4058</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4059.html">CVE-2008-4059</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4060.html">CVE-2008-4060</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4061.html">CVE-2008-4061</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4062.html">CVE-2008-4062</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4065.html">CVE-2008-4065</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4066.html">CVE-2008-4066</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4067.html">CVE-2008-4067</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4068.html">CVE-2008-4068</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4070.html">CVE-2008-4070</cve>
                <bugzilla href="http://bugzilla.redhat.com/463181" id="463181">CVE-2008-0016 Mozilla UTF-8 stack buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463182" id="463182">CVE-2008-3835 mozilla: nsXMLDocument::OnChannelRedirect() same-origin violation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463190" id="463190">CVE-2008-4058 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463192" id="463192">CVE-2008-4059 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463198" id="463198">CVE-2008-4060 Mozilla privilege escalation via XPCnativeWrapper pollution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463199" id="463199">CVE-2008-4061 Mozilla layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463201" id="463201">CVE-2008-4062 Mozilla crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463234" id="463234">CVE-2008-4065 Mozilla BOM characters stripped from JavaScript before execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463243" id="463243">CVE-2008-4066 Mozilla low surrogates stripped from JavaScript before execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463246" id="463246">CVE-2008-4067 Mozilla resource: traversal vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463248" id="463248">CVE-2008-4068 Mozilla local HTML file recource: bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464041" id="464041">CVE-2008-4070 Thunderbird cancelled newsgrop messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080908002" comment="thunderbird is earlier than 0:2.0.0.17-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080908005" comment="thunderbird is earlier than 0:1.5.0.12-16.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080937" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0937: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0937-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0937.html" />
          <reference source="CVE" ref_id="CVE-2008-3639" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3639.html" />
          <reference source="CVE" ref_id="CVE-2008-3640" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3640.html" />
          <reference source="CVE" ref_id="CVE-2008-3641" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3641.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX(R) operating systems.

A buffer overflow flaw was discovered in the SGI image format decoding
routines used by the CUPS image converting filter "imagetops". An attacker
could create a malicious SGI image file that could, possibly, execute
arbitrary code as the "lp" user if the file was printed. (CVE-2008-3639)

An integer overflow flaw leading to a heap buffer overflow was discovered
in the Text-to-PostScript "texttops" filter. An attacker could create a
malicious text file that could, possibly, execute arbitrary code as the
"lp" user if the file was printed. (CVE-2008-3640)

An insufficient buffer bounds checking flaw was discovered in the
HP-GL/2-to-PostScript "hpgltops" filter. An attacker could create a
malicious HP-GL/2 file that could, possibly, execute arbitrary code as the
"lp" user if the file was printed. (CVE-2008-3641)

Red Hat would like to thank regenrecht for reporting these issues.

All CUPS users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-10" />
        <updated date="2008-10-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3639.html">CVE-2008-3639</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3640.html">CVE-2008-3640</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3641.html">CVE-2008-3641</cve>
                <bugzilla href="http://bugzilla.redhat.com/464710" id="464710">CVE-2008-3639 CUPS: SGI image parser heap-based buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464713" id="464713">CVE-2008-3640 CUPS: texttops integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464716" id="464716">CVE-2008-3641 CUPS: HP/GL reader insufficient bounds checking</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937006" comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937008" comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937004" comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937002" comment="cups is earlier than 1:1.2.4-11.18.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937013" comment="cups-devel is earlier than 1:1.1.17-13.3.54" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937015" comment="cups-libs is earlier than 1:1.1.17-13.3.54" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937011" comment="cups is earlier than 1:1.1.17-13.3.54" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937019" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937020" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080937018" comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080939" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0939: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0939-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0939.html" />
          <reference source="CVE" ref_id="CVE-2008-2237" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2237.html" />
          <reference source="CVE" ref_id="CVE-2008-2238" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2238.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications such as a word processor, spreadsheet, presentation manager,
formula editor, and drawing program.

SureRun Security Team discovered an integer overflow flaw leading to a heap
buffer overflow in the Windows Metafile (WMF) image format parser. An
attacker could create a carefully crafted document containing a malicious
WMF file that could cause OpenOffice.org to crash, or, possibly, execute
arbitrary code if opened by a victim. (CVE-2008-2237)

Multiple integer overflow flaws were found in the Enhanced Windows Metafile
(EMF) parser. An attacker could create a carefully crafted document
containing a malicious EMF file that could cause OpenOffice.org to crash,
or, possibly, execute arbitrary code if opened by a victim. (CVE-2008-2238)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-05" />
        <updated date="2008-11-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2237.html">CVE-2008-2237</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2238.html">CVE-2008-2238</cve>
                <bugzilla href="http://bugzilla.redhat.com/462639" id="462639">CVE-2008-2237 OpenOffice.org WMF integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466528" id="466528">CVE-2008-2238 OpenOffice.org multiple EMF buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939136" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175073" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939002" comment="openoffice.org is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939048" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175149" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939084" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175079" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939154" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175095" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939138" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175101" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939050" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175119" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939060" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175089" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939010" comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175125" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939016" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175047" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939102" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175031" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939078" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175043" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939074" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175017" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939046" comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537025" comment="openoffice.org-headless is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939068" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175107" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939140" comment="openoffice.org-base is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175051" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939018" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175097" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939012" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175077" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939148" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175009" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939090" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175103" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939044" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175131" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939096" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175067" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939112" comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175135" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939108" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175133" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939104" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175147" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939058" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175029" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939026" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175109" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939082" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175115" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939122" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175049" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939152" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175081" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939066" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175023" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939106" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175037" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939004" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175025" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939022" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175105" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939072" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175111" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939028" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175007" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939070" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175145" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939030" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175011" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939076" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175063" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939150" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175015" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939092" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175075" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939132" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175035" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939064" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175013" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939100" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175127" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939062" comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175113" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939128" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175069" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939040" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175039" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939110" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175027" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939116" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537155" comment="openoffice.org-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939036" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175129" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939088" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175143" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939038" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175137" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939146" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175093" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939020" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175123" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939014" comment="openoffice.org-math is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175045" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939032" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175057" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939034" comment="openoffice.org-core is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175085" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939042" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175033" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939054" comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175141" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939118" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175099" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939124" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175121" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939130" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175021" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939098" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175091" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939144" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175055" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939006" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175071" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939056" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175117" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939080" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080537121" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939094" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175065" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939120" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175139" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939024" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175005" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939052" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175041" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939114" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175061" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939142" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175087" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939134" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175059" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939008" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175019" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939086" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175053" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939126" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.4.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175083" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939161" comment="openoffice.org-i18n is earlier than 0:1.1.2-43.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939157" comment="openoffice.org is earlier than 0:1.1.2-43.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939159" comment="openoffice.org-libs is earlier than 0:1.1.2-43.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939166" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.7.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176007" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939164" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.7.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176003" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939167" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.7.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176013" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939165" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.7.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080176005" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939281" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175244" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939263" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175184" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939245" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175262" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939215" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175258" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939197" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175214" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939185" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175266" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939183" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175176" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939173" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175228" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939265" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175218" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939261" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175226" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939233" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175208" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939203" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175186" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939191" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175252" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939225" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175194" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939223" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175230" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939201" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175192" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939213" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175160" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939205" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175220" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939177" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175242" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939179" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175206" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939169" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175152" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939279" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175250" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939273" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175174" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939271" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175212" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939255" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175178" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939249" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175256" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939243" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175216" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939241" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175248" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939237" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175164" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939227" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175158" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939209" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175182" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939193" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175154" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939187" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175240" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939247" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175224" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939235" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175264" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939229" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175210" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939199" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175234" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939171" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175162" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939277" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175156" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939275" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175202" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939269" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175170" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939251" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175190" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939219" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175260" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939211" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175236" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939195" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175246" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939181" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175254" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939259" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175222" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939257" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175168" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939253" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175172" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939221" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175232" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939285" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175200" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939283" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175268" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939267" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175166" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939239" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175198" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939231" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175238" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939207" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175180" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939189" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175188" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939175" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175196" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080939217" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.0" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080175204" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080945" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:0945: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0945-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0945.html" />
          <reference source="CVE" ref_id="CVE-2007-4324" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4324.html" />
          <reference source="CVE" ref_id="CVE-2007-6243" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6243.html" />
          <reference source="CVE" ref_id="CVE-2008-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3873.html" />
          <reference source="CVE" ref_id="CVE-2008-4401" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4401.html" />
          <reference source="CVE" ref_id="CVE-2008-4503" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4503.html" />
          <reference source="CVE" ref_id="CVE-2008-4818" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4818.html" />
          <reference source="CVE" ref_id="CVE-2008-4819" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4819.html" />
          <reference source="CVE" ref_id="CVE-2008-4821" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4821.html" />
          <reference source="CVE" ref_id="CVE-2008-4822" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4822.html" />
          <reference source="CVE" ref_id="CVE-2008-4823" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4823.html" />
          <reference source="CVE" ref_id="CVE-2008-4824" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4824.html" />
          <reference source="CVE" ref_id="CVE-2008-5361" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5361.html" />
          <reference source="CVE" ref_id="CVE-2008-5362" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5362.html" />
          <reference source="CVE" ref_id="CVE-2008-5363" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5363.html" />
    
    <description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
Web browser plug-in.

A flaw was found in the way Adobe Flash Player wrote content to the
clipboard. A malicious SWF file could populate the clipboard with a URL
that could cause the user to mistakenly load an attacker-controlled URL.
(CVE-2008-3873)

A flaw was found which allowed Adobe Flash Player's ActionScript to
initiate file uploads and downloads without user interaction.
FileReference.browse and FileReference.download calls can now only be
initiated via user interaction, such as mouse-clicks or key-presses on the
keyboard. (CVE-2008-4401)

A flaw was found in Adobe Flash Player's display of the Settings Manager
content. A malicious SWF file could trick the user into unknowingly
clicking a link or dialog. This could then give the malicious SWF file
permission to access the local machine's camera or microphone.
(CVE-2008-4503)

Flaws were found in the way Flash Player restricted the interpretation and
usage of cross-domain policy files.  A remote attacker could use Flash
Player to conduct cross-domain and cross-site scripting attacks
(CVE-2007-4324, CVE-2007-6243). This update provides enhanced fixes for
these issues.

Adobe Flash Player 10 also includes bug fixes and feature enhancements
including:

* improved stability on the Linux platform by fixing a race condition issue
in sound output.

* new support for custom filters and effects, native 3D transformation and
animation, advanced audio processing, a new, more flexible text engine, and
GPU hardware acceleration. 

For more information on new features and enhancements, see the Adobe Flash
Player site and the Adobe Labs Release Notes.

Note: some users may have installed a 3rd-party component, libflashsupport,
for older versions of Flash Player. Adobe Flash Player 10 no longer
supports libflashsupport. Users are advised to remove libflashsupport if
they have it installed.

All users of Adobe Flash Player should upgrade to this updated package,
which contains Flash Player version 10.0.12.36.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-28" />
        <updated date="2008-11-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4324.html">CVE-2007-4324</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6243.html">CVE-2007-6243</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3873.html">CVE-2008-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4401.html">CVE-2008-4401</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4503.html">CVE-2008-4503</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4818.html">CVE-2008-4818</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4819.html">CVE-2008-4819</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4821.html">CVE-2008-4821</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4822.html">CVE-2008-4822</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4823.html">CVE-2008-4823</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4824.html">CVE-2008-4824</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5361.html">CVE-2008-5361</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5362.html">CVE-2008-5362</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5363.html">CVE-2008-5363</cve>
                <bugzilla href="http://bugzilla.redhat.com/252292" id="252292">CVE-2007-4324 Flash movie can determine whether a TCP port is open</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440664" id="440664">CVE-2007-6243 Flash Player cross-domain and cross-site scripting flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465736" id="465736">CVE-2008-3873 flash: clipboard hijack attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466154" id="466154">CVE-2008-4401 flash-plugin: upload/download user interaction</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466344" id="466344">CVE-2008-4503 Adobe Flash Player clickjacking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470116" id="470116">CVE-2008-4818 Flash Player XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470123" id="470123">CVE-2008-4819 Flash Player DNS rebind attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470128" id="470128">CVE-2008-4823 Flash Player HTML injection flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470130" id="470130">CVE-2008-4822 Flash Player policy file interpretation flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470131" id="470131">CVE-2008-4821 Flash Player jar: protocol handler</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080945002" comment="flash-plugin is earlier than 0:10.0.12.36-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080221003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080946" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0946: ed security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0946-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0946.html" />
          <reference source="CVE" ref_id="CVE-2008-3916" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3916.html" />
    
    <description>ed is a line-oriented text editor, used to create, display, and modify
text files (both interactively and via shell scripts).

A heap-based buffer overflow was discovered in the way ed, the GNU line
editor, processed long file names. An attacker could create a file with a
specially-crafted name that could possibly execute an arbitrary code when
opened in the ed editor. (CVE-2008-3916)

Users of ed should upgrade to this updated package, which contains
a backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-21" />
        <updated date="2008-10-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3916.html">CVE-2008-3916</cve>
                <bugzilla href="http://bugzilla.redhat.com/462584" id="462584">CVE-2008-3916 ed: Heap-based buffer overflow (arb. code execution)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080946002" comment="ed is earlier than 0:0.2-39.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080946003" comment="ed is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080946005" comment="ed is earlier than 0:0.2-33.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080946006" comment="ed is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080946008" comment="ed is earlier than 0:0.2-36.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080946006" comment="ed is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080955" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0955: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0955-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0955.html" />
          <reference source="CVE" ref_id="CVE-2008-3104" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3104.html" />
          <reference source="CVE" ref_id="CVE-2008-3112" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3112.html" />
          <reference source="CVE" ref_id="CVE-2008-3113" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3113.html" />
          <reference source="CVE" ref_id="CVE-2008-3114" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3114.html" />
    
    <description>IBM's 1.4.2 SR12 Java release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

Multiple vulnerabilities with unsigned applets were reported. A remote
attacker could misuse an unsigned applet to connect to localhost services
running on the host running the applet. (CVE-2008-3104)

Two file processing vulnerabilities in Java Web Start were found. Using an
untrusted Java Web Start application, a remote attacker was able to create
or delete arbitrary files with the permissions of the user running the
untrusted application. (CVE-2008-3112, CVE-2008-3113)

A vulnerability in Java Web Start when processing untrusted applications
was reported. An attacker was able to acquire sensitive information, such
as the cache location. (CVE-2008-3114)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain IBM's 1.4.2 SR12 Java release which resolves these
issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-25" />
        <updated date="2008-11-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3104.html">CVE-2008-3104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3112.html">CVE-2008-3112</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3113.html">CVE-2008-3113</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3114.html">CVE-2008-3114</cve>
                <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454606" id="454606">CVE-2008-3112 Java Web Start, arbitrary file creation (6703909)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454607" id="454607">CVE-2008-3113 Java Web Start arbitrary file creation/deletion file with user permissions (6704077)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454608" id="454608">CVE-2008-3114 Java Web Start, untrusted application may determine Cache Location  (6704074)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955008" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132007" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955006" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955004" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132009" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955012" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132005" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080955010" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.12-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080132013" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080957" version="504" class="patch">
      <metadata>
        <title>RHSA-2008:0957: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0957-03" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0957.html" />
          <reference source="CVE" ref_id="CVE-2006-5755" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-5755.html" />
          <reference source="CVE" ref_id="CVE-2007-5907" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5907.html" />
          <reference source="CVE" ref_id="CVE-2008-2372" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2372.html" />
          <reference source="CVE" ref_id="CVE-2008-3276" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3276.html" />
          <reference source="CVE" ref_id="CVE-2008-3527" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3527.html" />
          <reference source="CVE" ref_id="CVE-2008-3833" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3833.html" />
          <reference source="CVE" ref_id="CVE-2008-4210" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4210.html" />
          <reference source="CVE" ref_id="CVE-2008-4302" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4302.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* the Xen implementation did not prevent applications running in a
para-virtualized guest from modifying CR4 TSC. This could cause a local
denial of service. (CVE-2007-5907, Important)

* Tavis Ormandy reported missing boundary checks in the Virtual Dynamic
Shared Objects (vDSO) implementation. This could allow a local unprivileged
user to cause a denial of service or escalate privileges. (CVE-2008-3527,
Important)

* the do_truncate() and generic_file_splice_write() functions did not clear
the setuid and setgid bits. This could allow a local unprivileged user to
obtain access to privileged information. (CVE-2008-4210, CVE-2008-3833,
Important)

* a flaw was found in the Linux kernel splice implementation. This could
cause a local denial of service when there is a certain failure in the
add_to_page_cache_lru() function. (CVE-2008-4302, Important)

* a flaw was found in the Linux kernel when running on AMD64 systems.
During a context switch, EFLAGS were being neither saved nor restored. This
could allow a local unprivileged user to cause a denial of service.
(CVE-2006-5755, Low)

* a flaw was found in the Linux kernel virtual memory implementation. This
could allow a local unprivileged user to cause a denial of service.
(CVE-2008-2372, Low)

* an integer overflow was discovered in the Linux kernel Datagram
Congestion Control Protocol (DCCP) implementation. This could allow a
remote attacker to cause a denial of service. By default, remote DCCP is
blocked by SELinux. (CVE-2008-3276, Low)

In addition, these updated packages fix the following bugs:

* random32() seeding has been improved. 

* in a multi-core environment, a race between the QP async event-handler
and the destro_qp() function could occur. This led to unpredictable results
during invalid memory access, which could lead to a kernel crash.

* a format string was omitted in the call to the request_module() function.

* a stack overflow caused by an infinite recursion bug in the binfmt_misc
kernel module was corrected.

* the ata_scsi_rbuf_get() and ata_scsi_rbuf_put() functions now check for
scatterlist usage before calling kmap_atomic().

* a sentinel NUL byte was added to the device_write() function to ensure
that lspace.name is NUL-terminated.

* in the character device driver, a range_is_allowed() check was added to
the read_mem() and write_mem() functions. It was possible for an
illegitimate application to bypass these checks, and access /dev/mem beyond
the 1M limit by calling mmap_mem() instead. Also, the parameters of
range_is_allowed() were changed to cleanly handle greater than 32-bits of
physical address on 32-bit architectures.

* some of the newer Nehalem-based systems declare their CPU DSDT entries as
type "Alias". During boot, this caused an "Error attaching device data"
message to be logged.

* the evtchn event channel device lacked locks and memory barriers. This
has led to xenstore becoming unresponsive on the Itanium® architecture.

* sending of gratuitous ARP packets in the Xen frontend network driver is
now delayed until the backend signals that its carrier status has been
processed by the stack.

* on forcedeth devices, whenever setting ethtool parameters for link speed,
the device could stop receiving interrupts.

* the CIFS 'forcedirectio' option did not allow text to be appended to files.

* the gettimeofday() function returned a backwards time on Intel® 64.

* residual-count corrections during UNDERRUN handling were added to the
qla2xxx driver.                                                   

* the fix for a small quirk was removed for certain Adaptec controllers for
which it caused problems.

* the "xm trigger init" command caused a domain panic if a userland
application was running on a guest on the Intel® 64 architecture.

Users of kernel should upgrade to these updated packages, which contain
backported patches to correct these issues. </description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-04" />
        <updated date="2008-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-5755.html">CVE-2006-5755</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5907.html">CVE-2007-5907</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2372.html">CVE-2008-2372</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3276.html">CVE-2008-3276</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3527.html">CVE-2008-3527</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3833.html">CVE-2008-3833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4210.html">CVE-2008-4210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4302.html">CVE-2008-4302</cve>
                <bugzilla href="http://bugzilla.redhat.com/377561" id="377561">CVE-2007-5907 kernel-xen 3.1.1 does not prevent modification of the CR4 TSC from  applications (DoS possible)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452666" id="452666">CVE-2008-2372 kernel: Reinstate ZERO_PAGE optimization in 'get_user_pages()' and fix XIP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457718" id="457718">CVE-2006-5755 kernel: local denial of service due to NT bit leakage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458021" id="458021">kernel: random32: seeding improvement [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458759" id="458759">kernel: dlm: dlm/user.c input validation fixes [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458781" id="458781">LTC44618-Race possibility between QP async handler and destroy_qp()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459226" id="459226">CVE-2008-3276 Linux kernel dccp_setsockopt_change() integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459461" id="459461">kernel: cpufreq: fix format string bug [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459464" id="459464">kernel: binfmt_misc.c: avoid potential kernel stack overflow [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460251" id="460251">CVE-2008-3527 kernel: missing boundary checks in syscall/syscall32_nopage()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460638" id="460638">[REG][5.3] The system crashed by the NULL pointer access with kmap_atomic() of ata_scsi_rbuf_get().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460858" id="460858">kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-5.2.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460868" id="460868">RHEL5.2  ACPI core bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461099" id="461099">evtchn device lacks lock and barriers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461457" id="461457">Coordinate gratuitous ARP with backend network status</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461894" id="461894">nVidia MCP55 MCP55 Ethernet (rev a3) not functional on kernel 2.6.18-53.1.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462434" id="462434">CVE-2008-4302 kernel: splice: fix bad unlock_page() in error case</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462591" id="462591">CIFS option forcedirectio fails to allow the appending of text to files.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462860" id="462860">RHEL5.3: Fix time of gettimeofday() going backward (EM64T) (*)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463661" id="463661">CVE-2008-4210 kernel: open() call allows setgid bit when user is not in new file's group</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464450" id="464450">CVE-2008-3833 kernel: remove SUID when splicing into an inode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465741" id="465741">[QLogic 5.2.z bug] qla2xxx - Additional residual-count corrections during UNDERRUN handling.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466427" id="466427">Significant regression in time() performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466885" id="466885">[aacraid 5.2.z] aac_srb: aac_fib_send failed with status 8195</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467105" id="467105">xm trigger &lt;domain> init causes kernel panic.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470040" id="470040">kernel-xen doesn't boot on Dell Optiplex GX280</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957004" comment="kernel-headers is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957002" comment="kernel is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957024" comment="kernel-doc is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957020" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957008" comment="kernel-devel is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957006" comment="kernel-debug is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957018" comment="kernel-kdump is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957014" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957012" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957022" comment="kernel-PAE is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957016" comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080957010" comment="kernel-xen is earlier than 0:2.6.18-92.1.18.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080965" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0965: lynx security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0965-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0965.html" />
          <reference source="CVE" ref_id="CVE-2008-4690" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4690.html" />
          <reference source="CVE" ref_id="CVE-2006-7234" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-7234.html" />
    
    <description>Lynx is a text-based Web browser.

An arbitrary command execution flaw was found in the Lynx "lynxcgi:" URI
handler. An attacker could create a web page redirecting to a malicious URL
that could execute arbitrary code as the user running Lynx in the
non-default "Advanced" user mode. (CVE-2008-4690)

Note: In these updated lynx packages, Lynx will always prompt users before
loading a "lynxcgi:" URI. Additionally, the default lynx.cfg configuration
file now marks all "lynxcgi:" URIs as untrusted by default.

A flaw was found in a way Lynx handled ".mailcap" and ".mime.types"
configuration files. Files in the browser's current working directory were
opened before those in the user's home directory. A local attacker, able to
convince a user to run Lynx in a directory under their control, could
possibly execute arbitrary commands as the user running Lynx. (CVE-2006-7234)

All users of Lynx are advised to upgrade to this updated package, which
contains backported patches correcting these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-10-27" />
        <updated date="2008-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4690.html">CVE-2008-4690</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-7234.html">CVE-2006-7234</cve>
                <bugzilla href="http://bugzilla.redhat.com/214205" id="214205">CVE-2006-7234 lynx: .mailcap and .mime.types files read from CWD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468184" id="468184">CVE-2008-4690 lynx: remote arbitrary command execution via a crafted lynxcgi: URL</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080965002" comment="lynx is earlier than 0:2.8.5-28.1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080965003" comment="lynx is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080965005" comment="lynx is earlier than 0:2.8.5-11.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080965006" comment="lynx is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080965008" comment="lynx is earlier than 0:2.8.5-18.2.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080965006" comment="lynx is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080967" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0967: httpd security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0967-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0967.html" />
          <reference source="CVE" ref_id="CVE-2008-2364" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2364.html" />
          <reference source="CVE" ref_id="CVE-2008-2939" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2939.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the mod_proxy Apache module. An attacker in control of
a Web server to which requests were being proxied could have caused a
limited denial of service due to CPU consumption and stack exhaustion.
(CVE-2008-2364)

A flaw was found in the mod_proxy_ftp Apache module. If Apache was
configured to support FTP-over-HTTP proxying, a remote attacker could have
performed a cross-site scripting attack. (CVE-2008-2939)

In addition, these updated packages fix a bug found in the handling of the
"ProxyRemoteMatch" directive in the Red Hat Enterprise Linux 4 httpd
packages. This bug is not present in the Red Hat Enterprise Linux 3 or Red
Hat Enterprise Linux 5 packages.

Users of httpd should upgrade to these updated packages, which contain
backported patches to correct these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-11" />
        <updated date="2008-11-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2364.html">CVE-2008-2364</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2939.html">CVE-2008-2939</cve>
                <bugzilla href="http://bugzilla.redhat.com/451615" id="451615">CVE-2008-2364 httpd: mod_proxy_http DoS via excessive interim responses from the origin server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458250" id="458250">CVE-2008-2939 httpd: mod_proxy_ftp globbing XSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464492" id="464492">mod_proxy: ProxyRemoteMatch uses remote proxy if regex does *not* match</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967008" comment="httpd-manual is earlier than 0:2.2.3-11.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008007" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967006" comment="httpd-devel is earlier than 0:2.2.3-11.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008005" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967004" comment="mod_ssl is earlier than 0:2.2.3-11.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008009" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967002" comment="httpd is earlier than 0:2.2.3-11.el5_2.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080008003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967013" comment="httpd-devel is earlier than 0:2.0.46-71.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967015" comment="mod_ssl is earlier than 0:2.0.46-71.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967011" comment="httpd is earlier than 0:2.0.46-71.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967023" comment="httpd-manual is earlier than 0:2.0.52-41.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080006011" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967022" comment="httpd-devel is earlier than 0:2.0.52-41.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005007" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967020" comment="httpd-suexec is earlier than 0:2.0.52-41.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080006009" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967019" comment="mod_ssl is earlier than 0:2.0.52-41.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005005" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080967018" comment="httpd is earlier than 0:2.0.52-41.ent.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080005003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080971" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0971: net-snmp security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0971-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0971.html" />
          <reference source="CVE" ref_id="CVE-2008-4309" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4309.html" />
    
    <description>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

A denial-of-service flaw was found in the way Net-SNMP processes SNMP
GETBULK requests. A remote attacker who issued a specially-crafted request
could cause the snmpd server to crash. (CVE-2008-4309)

Note: An attacker must have read access to the SNMP server in order to
exploit this flaw. In the default configuration, the community name
"public" grants read-only access. In production deployments, it is
recommended to change this default community name.

All users of net-snmp should upgrade to these updated packages, which
contain a backported patch to resolve this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-03" />
        <updated date="2008-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4309.html">CVE-2008-4309</cve>
                <bugzilla href="http://bugzilla.redhat.com/469349" id="469349">CVE-2008-4309 net-snmp: numresponses calculation integer overflow in snmp_agent.c</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971010" comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529007" comment="net-snmp-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971006" comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529011" comment="net-snmp-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971008" comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529005" comment="net-snmp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971004" comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529009" comment="net-snmp-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971002" comment="net-snmp is earlier than 1:5.3.1-24.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529003" comment="net-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971017" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529018" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971021" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529020" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971019" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529022" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971015" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529016" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971013" comment="net-snmp is earlier than 0:5.0.9-2.30E.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529014" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971027" comment="net-snmp-utils is earlier than 0:5.1.2-13.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529018" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971026" comment="net-snmp-libs is earlier than 0:5.1.2-13.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529020" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971028" comment="net-snmp-devel is earlier than 0:5.1.2-13.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529016" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971025" comment="net-snmp-perl is earlier than 0:5.1.2-13.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529022" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080971024" comment="net-snmp is earlier than 0:5.1.2-13.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080529014" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080972" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0972: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0972-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0972.html" />
          <reference source="CVE" ref_id="CVE-2008-3272" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3272.html" />
          <reference source="CVE" ref_id="CVE-2007-6716" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6716.html" />
          <reference source="CVE" ref_id="CVE-2007-5093" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5093.html" />
          <reference source="CVE" ref_id="CVE-2008-1514" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1514.html" />
          <reference source="CVE" ref_id="CVE-2008-3528" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3528.html" />
          <reference source="CVE" ref_id="CVE-2008-4210" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4210.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* a flaw was found in the Linux kernel's Direct-IO implementation. This
could have allowed a local unprivileged user to cause a denial of service.
(CVE-2007-6716, Important)

* when running ptrace in 31-bit mode on an IBM S/390 or IBM System z
kernel, a local unprivileged user could cause a denial of service by
reading from or writing into a padding area in the user_regs_struct32
structure. (CVE-2008-1514, Important)

* the do_truncate() and generic_file_splice_write() functions did not clear
the setuid and setgid bits. This could have allowed a local unprivileged
user to obtain access to privileged information. (CVE-2008-4210, Important)

* Tobias Klein reported a missing check in the Linux kernel's Open Sound
System (OSS) implementation. This deficiency could have led to an
information leak. (CVE-2008-3272, Moderate)

* a potential denial of service attack was discovered in the Linux kernel's
PWC USB video driver. A local unprivileged user could have used this flaw
to bring the kernel USB subsystem into the busy-waiting state.
(CVE-2007-5093, Low)

* the ext2 and ext3 file systems code failed to properly handle corrupted
data structures, leading to a possible local denial of service issue when
read or write operations were performed. (CVE-2008-3528, Low)

In addition, these updated packages fix the following bugs:

* when using the CIFS "forcedirectio" option, appending to an open file on
a CIFS share resulted in that file being overwritten with the data to be
appended.

* a kernel panic occurred when a device with PCI ID 8086:10c8 was present
on a system with a loaded ixgbe driver.

* due to an aacraid driver regression, the kernel failed to boot when trying
to load the aacraid driver and printed the following error message:
"aac_srb: aac_fib_send failed with status: 8195".

* due to an mpt driver regression, when RAID 1 was configured on Primergy
systems with an LSI SCSI IME 53C1020/1030 controller, the kernel panicked
during boot.

* the mpt driver produced a large number of extraneous debugging messages
when performing a "Host reset" operation.

* due to a regression in the sym driver, the kernel panicked when a SCSI
hot swap was performed using MCP18 hardware.

* all cores on a multi-core system now scale their frequencies in
accordance with the policy set by the system's CPU frequency governor.

* the netdump subsystem suffered from several stability issues. These are
addressed in this updated kernel.

* under certain conditions, the ext3 file system reported a negative count
of used blocks.

* reading /proc/self/mem incorrectly returned "Invalid argument" instead of
"input/output error" due to a regression.

* under certain conditions, the kernel panicked when a USB device was
removed while the system was busy accessing the device.

* a race condition in the kernel could have led to a kernel crash during
the creation of a new process.

All Red Hat Enterprise Linux 4 Users should upgrade to these updated
packages, which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-19" />
        <updated date="2008-11-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3272.html">CVE-2008-3272</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6716.html">CVE-2007-6716</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5093.html">CVE-2007-5093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1514.html">CVE-2008-1514</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3528.html">CVE-2008-3528</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4210.html">CVE-2008-4210</cve>
                <bugzilla href="http://bugzilla.redhat.com/306591" id="306591">CVE-2007-5093 kernel PWC driver DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438147" id="438147">CVE-2008-1514 kernel: ptrace: Padding area write - unprivileged kernel crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455770" id="455770">RHEL 4.6: scsi hot swap broken (sym / Nokia MCP18)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457995" id="457995">CVE-2008-3272 kernel snd_seq_oss_synth_make_info leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459577" id="459577">CVE-2008-3528 Linux kernel ext[234] directory corruption denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461082" id="461082">CVE-2007-6716 kernel: dio: zero struct dio with kzalloc instead of manually</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463661" id="463661">CVE-2008-4210 kernel: open() call allows setgid bit when user is not in new file's group</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464494" id="464494">CIFS option forcedirectio fails to allow the appending of text to files.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464496" id="464496">Negative used blocks reported with ext3 on RHEL4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464747" id="464747">regression, rhel4.7+, on the try to read /proc/self/mem getting improper return value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465232" id="465232">[4.7] When the USB device is removed while the system is accessing the USB device, the panic is done.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465265" id="465265">mpt 3.12.19.00rh on RHEL4.7 causes panic if a RAID 1 is configured.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465735" id="465735">RHEL 4.7 ixgbe driver has a recursive stack corruption problem.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466113" id="466113">netdump fails when bnx2 has remote copper PHY - Badness in local_bh_enable at kernel/softirq.c:141</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466214" id="466214">kernel BUG at kernel/signal.c:369! (attempt to free tsk->signal twice)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466217" id="466217">[REG][4.7]Outputting large amount of log message when issuing host reset to adapter.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468151" id="468151">aac_fib_send failed with status 8195</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469647" id="469647">add multi-core support to cpufreq driver</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972002" comment="kernel is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972022" comment="kernel-doc is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972004" comment="kernel-devel is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972012" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055007" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972020" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972008" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972006" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055015" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972016" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055017" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972014" comment="kernel-xenU is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055011" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055019" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080972010" comment="kernel-smp is earlier than 0:2.6.9-78.0.8.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080973" version="504" class="patch">
      <metadata>
        <title>RHSA-2008:0973: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0973-03" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0973.html" />
          <reference source="CVE" ref_id="CVE-2008-4210" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4210.html" />
          <reference source="CVE" ref_id="CVE-2008-3275" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3275.html" />
          <reference source="CVE" ref_id="CVE-2008-0598" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0598.html" />
          <reference source="CVE" ref_id="CVE-2008-2136" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2136.html" />
          <reference source="CVE" ref_id="CVE-2008-2812" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2812.html" />
          <reference source="CVE" ref_id="CVE-2007-6063" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6063.html" />
          <reference source="CVE" ref_id="CVE-2008-3525" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3525.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* Tavis Ormandy discovered a deficiency in the Linux kernel 32-bit and
64-bit emulation. This could allow a local, unprivileged user to prepare
and run a specially-crafted binary which would use this deficiency to leak
uninitialized and potentially sensitive data. (CVE-2008-0598, Important)

* a possible kernel memory leak was found in the Linux kernel Simple
Internet Transition (SIT) INET6 implementation. This could allow a local,
unprivileged user to cause a denial of service. (CVE-2008-2136, Important)

* missing capability checks were found in the SBNI WAN driver which could
allow a local user to bypass intended capability restrictions.
(CVE-2008-3525, Important)

* the do_truncate() and generic_file_splice_write() functions did not clear
the setuid and setgid bits. This could allow a local, unprivileged user to
obtain access to privileged information. (CVE-2008-4210, Important)

* a buffer overflow flaw was found in Integrated Services Digital Network
(ISDN) subsystem. A local, unprivileged user could use this flaw to cause a
denial of service. (CVE-2007-6063, Moderate)

* multiple NULL pointer dereferences were found in various Linux kernel
network drivers. These drivers were missing checks for terminal validity,
which could allow privilege escalation. (CVE-2008-2812, Moderate)

* a deficiency was found in the Linux kernel virtual filesystem (VFS)
implementation. This could allow a local, unprivileged user to attempt file
creation within deleted directories, possibly causing a denial of service.
(CVE-2008-3275, Moderate)

This update also fixes the following bugs:

* the incorrect kunmap function was used in nfs_xdr_readlinkres. kunmap()
was used where kunmap_atomic() should have been. As a consequence, if an
NFSv2 or NFSv3 server exported a volume containing a symlink which included
a path equal to or longer than the local system's PATH_MAX, accessing the
link caused a kernel oops. This has been corrected in this update.

* mptctl_gettargetinfo did not check if pIoc3 was NULL before using it as a
pointer. This caused a kernel panic in mptctl_gettargetinfo in some
circumstances. A check has been added which prevents this.

* lost tick compensation code in the timer interrupt routine triggered
without apparent cause. When running as a fully-virtualized client, this
spurious triggering caused the 64-bit version of Red Hat Enterprise Linux 3
to present highly inaccurate times. With this update the lost tick
compensation code is turned off when the operating system is running as a
fully-virtualized client under Xen or VMWare®.

All Red Hat Enterprise Linux 3 users should install this updated kernel
which addresses these vulnerabilities and fixes these bugs.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-16" />
        <updated date="2008-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4210.html">CVE-2008-4210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3275.html">CVE-2008-3275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0598.html">CVE-2008-0598</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2136.html">CVE-2008-2136</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2812.html">CVE-2008-2812</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6063.html">CVE-2007-6063</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3525.html">CVE-2008-3525</cve>
                <bugzilla href="http://bugzilla.redhat.com/392101" id="392101">CVE-2007-6063 Linux Kernel isdn_net_setcfg buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433938" id="433938">CVE-2008-0598 kernel: linux x86_64 ia32 emulation leaks uninitialized data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438758" id="438758">wrong kunmap call in nfs_xdr_readlinkres</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446031" id="446031">CVE-2008-2136 kernel: sit memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453419" id="453419">CVE-2008-2812 kernel: NULL ptr dereference in multiple network drivers due to missing checks in tty code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457858" id="457858">CVE-2008-3275 Linux kernel local filesystem DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460401" id="460401">CVE-2008-3525 kernel: missing capability checks in sbni_ioctl()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463661" id="463661">CVE-2008-4210 kernel: open() call allows setgid bit when user is not in new file's group</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973004" comment="kernel-source is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211013" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973002" comment="kernel is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973006" comment="kernel-doc is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973016" comment="kernel-hugemem is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055021" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973014" comment="kernel-BOOT is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973010" comment="kernel-smp-unsupported is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211009" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973012" comment="kernel-unsupported is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080211007" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080973008" comment="kernel-smp is earlier than 0:2.4.21-58.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080055013" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080974" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0974: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0974-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0974.html" />
          <reference source="CVE" ref_id="CVE-2008-2549" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2549.html" />
          <reference source="CVE" ref_id="CVE-2008-2992" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2992.html" />
          <reference source="CVE" ref_id="CVE-2008-4812" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4812.html" />
          <reference source="CVE" ref_id="CVE-2008-4813" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4813.html" />
          <reference source="CVE" ref_id="CVE-2008-4814" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4814.html" />
          <reference source="CVE" ref_id="CVE-2008-4815" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4815.html" />
          <reference source="CVE" ref_id="CVE-2008-4817" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4817.html" />
          <reference source="CVE" ref_id="CVE-2009-0927" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0927.html" />
    
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

Several input validation flaws were discovered in Adobe Reader. A malicious
PDF file could cause Adobe Reader to crash or, potentially, execute
arbitrary code as the user running Adobe Reader. (CVE-2008-2549,
CVE-2008-2992, CVE-2008-4812, CVE-2008-4813, CVE-2008-4814, CVE-2008-4817)

The Adobe Reader binary had an insecure relative RPATH (runtime library
search path) set in the ELF (Executable and Linking Format) header. A local
attacker able to convince another user to run Adobe Reader in an
attacker-controlled directory could run arbitrary code with the privileges
of the victim. (CVE-2008-4815)

All acroread users are advised to upgrade to these updated packages, that
contain Adobe Reader version 8.1.3, and are not vulnerable to these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-12" />
        <updated date="2008-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2549.html">CVE-2008-2549</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2992.html">CVE-2008-2992</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4812.html">CVE-2008-4812</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4813.html">CVE-2008-4813</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4814.html">CVE-2008-4814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4815.html">CVE-2008-4815</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4817.html">CVE-2008-4817</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0927.html">CVE-2009-0927</cve>
                <bugzilla href="http://bugzilla.redhat.com/450078" id="450078">CVE-2008-2549 acroread: crash and possible code execution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469875" id="469875">CVE-2008-4812 Adobe Reader: embedded font handling out-of-bounds array indexing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469876" id="469876">CVE-2008-4813 Adobe Reader: PDF objects parsing and JavaScript getCosObj handling memory corruption flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469877" id="469877">CVE-2008-2992 Adobe Reader: JavaScript util.printf() function buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469880" id="469880">CVE-2008-4814 Adobe Reader: arbitrary code execution via unspecified JavaScript method</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469882" id="469882">CVE-2008-4815 Adobe Reader: insecure RPATH flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469923" id="469923">CVE-2008-4817 Adobe Reader: Download Manager input validation flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080974004" comment="acroread-plugin is earlier than 0:8.1.3-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080144005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080974002" comment="acroread is earlier than 0:8.1.3-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080144003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080976" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0976: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0976-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0976.html" />
          <reference source="CVE" ref_id="CVE-2008-5014" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5014.html" />
          <reference source="CVE" ref_id="CVE-2008-5016" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5016.html" />
          <reference source="CVE" ref_id="CVE-2008-5017" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5017.html" />
          <reference source="CVE" ref_id="CVE-2008-5018" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5018.html" />
          <reference source="CVE" ref_id="CVE-2008-5021" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5021.html" />
          <reference source="CVE" ref_id="CVE-2008-5012" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5012.html" />
          <reference source="CVE" ref_id="CVE-2008-5022" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5022.html" />
          <reference source="CVE" ref_id="CVE-2008-5024" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5024.html" />
          <reference source="CVE" ref_id="CVE-2008-5052" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5052.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-5014, CVE-2008-5016, CVE-2008-5017, CVE-2008-5018,
CVE-2008-5021)

Several flaws were found in the way malformed HTML mail content was
processed. An HTML mail message containing specially-crafted content could
potentially trick a Thunderbird user into surrendering sensitive
information. (CVE-2008-5012, CVE-2008-5022, CVE-2008-5024)

All Thunderbird users should upgrade to these updated packages, which
resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-19" />
        <updated date="2008-11-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5014.html">CVE-2008-5014</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5016.html">CVE-2008-5016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5017.html">CVE-2008-5017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5018.html">CVE-2008-5018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5021.html">CVE-2008-5021</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5012.html">CVE-2008-5012</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5022.html">CVE-2008-5022</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5024.html">CVE-2008-5024</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5052.html">CVE-2008-5052</cve>
                <bugzilla href="http://bugzilla.redhat.com/470864" id="470864">CVE-2008-5012 Mozilla Image stealing via canvas and HTTP redirect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470873" id="470873">CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470881" id="470881">CVE-2008-5016 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470883" id="470883">CVE-2008-5017 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470884" id="470884">CVE-2008-5018 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470894" id="470894">CVE-2008-5021 Mozilla crash and remote code execution in nsFrameManager</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470895" id="470895">CVE-2008-5022 Mozilla nsXMLHttpRequest::NotifyEventListeners() same-origin violation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470902" id="470902">CVE-2008-5024 Mozilla parsing error in E4X default namespace</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080976002" comment="thunderbird is earlier than 0:2.0.0.18-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080976005" comment="thunderbird is earlier than 0:1.5.0.12-17.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080105006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080977" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0977: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0977-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0977.html" />
          <reference source="CVE" ref_id="CVE-2008-0017" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0017.html" />
          <reference source="CVE" ref_id="CVE-2008-5012" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5012.html" />
          <reference source="CVE" ref_id="CVE-2008-5013" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5013.html" />
          <reference source="CVE" ref_id="CVE-2008-5014" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5014.html" />
          <reference source="CVE" ref_id="CVE-2008-5016" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5016.html" />
          <reference source="CVE" ref_id="CVE-2008-5017" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5017.html" />
          <reference source="CVE" ref_id="CVE-2008-5018" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5018.html" />
          <reference source="CVE" ref_id="CVE-2008-5019" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5019.html" />
          <reference source="CVE" ref_id="CVE-2008-5021" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5021.html" />
          <reference source="CVE" ref_id="CVE-2008-5022" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5022.html" />
          <reference source="CVE" ref_id="CVE-2008-5023" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5023.html" />
          <reference source="CVE" ref_id="CVE-2008-5024" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5024.html" />
          <reference source="CVE" ref_id="CVE-2008-5052" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5052.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-0017, CVE-2008-5013, CVE-2008-5014, CVE-2008-5016,
CVE-2008-5017, CVE-2008-5018, CVE-2008-5019, CVE-2008-5021)

Several flaws were found in the way malformed content was processed. A web
site containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-5012,
CVE-2008-5022, CVE-2008-5023, CVE-2008-5024)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-12" />
        <updated date="2008-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0017.html">CVE-2008-0017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5012.html">CVE-2008-5012</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5013.html">CVE-2008-5013</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5014.html">CVE-2008-5014</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5016.html">CVE-2008-5016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5017.html">CVE-2008-5017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5018.html">CVE-2008-5018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5019.html">CVE-2008-5019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5021.html">CVE-2008-5021</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5022.html">CVE-2008-5022</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5023.html">CVE-2008-5023</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5024.html">CVE-2008-5024</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5052.html">CVE-2008-5052</cve>
                <bugzilla href="http://bugzilla.redhat.com/470864" id="470864">CVE-2008-5012 Mozilla Image stealing via canvas and HTTP redirect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470867" id="470867">CVE-2008-5013 Mozilla Flash Player dynamic module unloading flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470873" id="470873">CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470881" id="470881">CVE-2008-5016 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470883" id="470883">CVE-2008-5017 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470884" id="470884">CVE-2008-5018 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470889" id="470889">CVE-2008-5019 Mozilla XSS via session restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470892" id="470892">CVE-2008-0017 Mozilla buffer overflow in http-index-format parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470894" id="470894">CVE-2008-5021 Mozilla crash and remote code execution in nsFrameManager</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470895" id="470895">CVE-2008-5022 Mozilla nsXMLHttpRequest::NotifyEventListeners() same-origin violation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470898" id="470898">CVE-2008-5023 Mozilla -moz-binding property bypasses security checks on codebase principals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470902" id="470902">CVE-2008-5024 Mozilla parsing error in E4X default namespace</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977008" comment="seamonkey-nspr is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977006" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977004" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977016" comment="seamonkey-mail is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977002" comment="seamonkey is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977018" comment="seamonkey-devel is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977020" comment="seamonkey-nss is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977012" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977010" comment="seamonkey-chat is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977014" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977026" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-28.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977024" comment="seamonkey-mail is earlier than 0:1.0.9-28.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977023" comment="seamonkey is earlier than 0:1.0.9-28.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977025" comment="seamonkey-devel is earlier than 0:1.0.9-28.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977028" comment="seamonkey-chat is earlier than 0:1.0.9-28.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080977027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-28.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080978" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0978: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0978-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0978.html" />
          <reference source="CVE" ref_id="CVE-2008-0017" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-0017.html" />
          <reference source="CVE" ref_id="CVE-2008-5014" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5014.html" />
          <reference source="CVE" ref_id="CVE-2008-5015" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5015.html" />
          <reference source="CVE" ref_id="CVE-2008-5016" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5016.html" />
          <reference source="CVE" ref_id="CVE-2008-5017" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5017.html" />
          <reference source="CVE" ref_id="CVE-2008-5018" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5018.html" />
          <reference source="CVE" ref_id="CVE-2008-5019" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5019.html" />
          <reference source="CVE" ref_id="CVE-2008-5021" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5021.html" />
          <reference source="CVE" ref_id="CVE-2008-5022" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5022.html" />
          <reference source="CVE" ref_id="CVE-2008-5023" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5023.html" />
          <reference source="CVE" ref_id="CVE-2008-5024" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5024.html" />
          <reference source="CVE" ref_id="CVE-2008-5052" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5052.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-0017, CVE-2008-5014, CVE-2008-5016, CVE-2008-5017,
CVE-2008-5018, CVE-2008-5019, CVE-2008-5021)

Several flaws were found in the way malformed content was processed. A web
site containing specially-crafted content could potentially trick a Firefox
user into surrendering sensitive information. (CVE-2008-5022,
CVE-2008-5023, CVE-2008-5024)

A flaw was found in the way Firefox opened "file:" URIs. If a file: URI was
loaded in the same tab as a chrome or privileged "about:" page, the file:
URI could execute arbitrary code with the permissions of the user running
Firefox. (CVE-2008-5015)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.4. You can find a link to the Mozilla
advisories in the References section.

All firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-12" />
        <updated date="2008-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-0017.html">CVE-2008-0017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5014.html">CVE-2008-5014</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5015.html">CVE-2008-5015</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5016.html">CVE-2008-5016</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5017.html">CVE-2008-5017</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5018.html">CVE-2008-5018</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5019.html">CVE-2008-5019</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5021.html">CVE-2008-5021</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5022.html">CVE-2008-5022</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5023.html">CVE-2008-5023</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5024.html">CVE-2008-5024</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5052.html">CVE-2008-5052</cve>
                <bugzilla href="http://bugzilla.redhat.com/454283" id="454283">firefox-2.0-getstartpage.patch breaks extensions which set homepage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470873" id="470873">CVE-2008-5014 Mozilla crash and remote code execution via __proto__ tampering</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470876" id="470876">CVE-2008-5015 Mozilla file: URIs inherit chrome privileges</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470881" id="470881">CVE-2008-5016 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470883" id="470883">CVE-2008-5017 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470884" id="470884">CVE-2008-5018 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470889" id="470889">CVE-2008-5019 Mozilla XSS via session restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470892" id="470892">CVE-2008-0017 Mozilla buffer overflow in http-index-format parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470894" id="470894">CVE-2008-5021 Mozilla crash and remote code execution in nsFrameManager</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470895" id="470895">CVE-2008-5022 Mozilla nsXMLHttpRequest::NotifyEventListeners() same-origin violation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470898" id="470898">CVE-2008-5023 Mozilla -moz-binding property bypasses security checks on codebase principals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470902" id="470902">CVE-2008-5024 Mozilla parsing error in E4X default namespace</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978002" comment="firefox is earlier than 0:3.0.4-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978008" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.4-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569007" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978004" comment="xulrunner is earlier than 0:1.9.0.4-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978006" comment="xulrunner-devel is earlier than 0:1.9.0.4-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978010" comment="nss is earlier than 0:3.12.1.1-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879009" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978016" comment="nss-tools is earlier than 0:3.12.1.1-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879015" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978014" comment="nss-pkcs11-devel is earlier than 0:3.12.1.1-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879011" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978012" comment="nss-devel is earlier than 0:3.12.1.1-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879013" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978018" comment="devhelp is earlier than 0:0.12-20.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569011" comment="devhelp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978020" comment="devhelp-devel is earlier than 0:0.12-20.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569013" comment="devhelp-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978022" comment="yelp is earlier than 0:2.16.0-22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569009" comment="yelp is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978025" comment="firefox is earlier than 0:3.0.4-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978027" comment="nss is earlier than 0:3.12.1.1-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080978028" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080978029" comment="nss-devel is earlier than 0:3.12.1.1-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080978030" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080981" version="505" class="patch">
      <metadata>
        <title>RHSA-2008:0981: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0981-04" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0981.html" />
          <reference source="CVE" ref_id="CVE-2008-4310" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4310.html" />
    
    <description>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

Vincent Danen reported, that Red Hat Security Advisory RHSA-2008:0897
did not properly address a denial of service flaw in the WEBrick (Ruby
HTTP server toolkit), known as CVE-2008-3656. This flaw allowed a
remote attacker to send a specially-crafted HTTP request to a WEBrick
server that would cause the server to use excessive CPU time. This
update properly addresses this flaw. (CVE-2008-4310)

All Ruby users should upgrade to these updated packages, which contain a
correct patch that resolves this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-04" />
        <updated date="2008-12-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4310.html">CVE-2008-4310</cve>
                <bugzilla href="http://bugzilla.redhat.com/470252" id="470252">CVE-2008-4310 ruby: Incomplete fix for CVE-2008-3656</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981010" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561005" comment="ruby-ri is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981008" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561015" comment="ruby-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981006" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561009" comment="ruby-mode is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981014" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561019" comment="ruby-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981004" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561013" comment="ruby-tcltk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981018" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561007" comment="ruby-irb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981016" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561011" comment="ruby-rdoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981002" comment="ruby is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561003" comment="ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981012" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561017" comment="ruby-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981033" comment="ruby-docs is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561028" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981029" comment="irb is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561032" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981025" comment="ruby-mode is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561026" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981031" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561030" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981023" comment="ruby-libs is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561034" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981021" comment="ruby is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561022" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080981027" comment="ruby-devel is earlier than 0:1.8.1-7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080561024" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080982" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0982: gnutls security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0982-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0982.html" />
          <reference source="CVE" ref_id="CVE-2008-4989" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4989.html" />
    
    <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS). 

Martin von Gagern discovered a flaw in the way GnuTLS verified certificate
chains provided by a server. A malicious server could use this flaw to
spoof its identity by tricking client applications using the GnuTLS library
to trust invalid certificates. (CVE-2008-4989)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-11" />
        <updated date="2008-11-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4989.html">CVE-2008-4989</cve>
                <bugzilla href="http://bugzilla.redhat.com/470079" id="470079">CVE-2008-4989 gnutls: certificate chain verification flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080982006" comment="gnutls-devel is earlier than 0:1.4.1-3.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080489005" comment="gnutls-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080982004" comment="gnutls-utils is earlier than 0:1.4.1-3.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080489007" comment="gnutls-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080982002" comment="gnutls is earlier than 0:1.4.1-3.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080489003" comment="gnutls is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20080988" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:0988: libxml2 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:0988-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-0988.html" />
          <reference source="CVE" ref_id="CVE-2008-4225" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4225.html" />
          <reference source="CVE" ref_id="CVE-2008-4226" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4226.html" />
    
    <description>libxml2 is a library for parsing and manipulating XML files. It includes
support for reading, modifying, and writing XML and HTML files.

An integer overflow flaw causing a heap-based buffer overflow was found in
the libxml2 XML parser. If an application linked against libxml2 processed
untrusted, malformed XML content, it could cause the application to crash
or, possibly, execute arbitrary code. (CVE-2008-4226)

A denial of service flaw was discovered in the libxml2 XML parser. If an
application linked against libxml2 processed untrusted, malformed XML
content, it could cause the application to enter an infinite loop.
(CVE-2008-4225)

Red Hat would like to thank Drew Yao of the Apple Product Security team for
reporting these issues.

Users of libxml2 are advised to upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-17" />
        <updated date="2008-11-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4225.html">CVE-2008-4225</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4226.html">CVE-2008-4226</cve>
                <bugzilla href="http://bugzilla.redhat.com/470466" id="470466">CVE-2008-4226 libxml2: integer overflow leading to memory corruption in  xmlSAX2Characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470480" id="470480">CVE-2008-4225 libxml2: integer overflow leading to infinite loop in xmlBufferResize</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988002" comment="libxml2 is earlier than 0:2.6.26-2.1.2.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032003" comment="libxml2 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988006" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032005" comment="libxml2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988004" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032007" comment="libxml2-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988009" comment="libxml2 is earlier than 0:2.5.10-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988013" comment="libxml2-devel is earlier than 0:2.5.10-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988011" comment="libxml2-python is earlier than 0:2.5.10-14" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988016" comment="libxml2 is earlier than 0:2.6.16-12.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032010" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988018" comment="libxml2-devel is earlier than 0:2.6.16-12.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032012" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080988017" comment="libxml2-python is earlier than 0:2.6.16-12.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080032014" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081001" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1001: tog-pegasus security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1001-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1001.html" />
          <reference source="CVE" ref_id="CVE-2008-4313" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4313.html" />
          <reference source="CVE" ref_id="CVE-2008-4315" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4315.html" />
    
    <description>The tog-pegasus packages provide OpenPegasus Web-Based Enterprise
Management (WBEM) services. WBEM is a platform and resource independent
Distributed Management Task Force (DMTF) standard that defines a common
information model and communication protocol for monitoring and controlling
resources.

Red Hat defines additional security enhancements for OpenGroup Pegasus WBEM
services in addition to those defined by the upstream OpenGroup Pegasus
release. For details regarding these enhancements, refer to the file
"README.RedHat.Security", included in the Red Hat tog-pegasus package.

After re-basing to version 2.7.0 of the OpenGroup Pegasus code, these
additional security enhancements were no longer being applied. As a
consequence, access to OpenPegasus WBEM services was not restricted to the
dedicated users as described in README.RedHat.Security. An attacker able to
authenticate using a valid user account could use this flaw to send
requests to WBEM services. (CVE-2008-4313)

Note: default SELinux policy prevents tog-pegasus from modifying system
files. This flaw's impact depends on whether or not tog-pegasus is confined
by SELinux, and on any additional CMPI providers installed and enabled on a
particular system.

Failed authentication attempts against the OpenPegasus CIM server were not
logged to the system log as documented in README.RedHat.Security. An
attacker could use this flaw to perform password guessing attacks against a
user account without leaving traces in the system log. (CVE-2008-4315)

All tog-pegasus users are advised to upgrade to these updated packages,
which contain patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-11-25" />
        <updated date="2008-11-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4313.html">CVE-2008-4313</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4315.html">CVE-2008-4315</cve>
                <bugzilla href="http://bugzilla.redhat.com/459217" id="459217">CVE-2008-4313 tog-pegasus: WBEM services access not restricted to dedicated user after 2.7.0 rebase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472017" id="472017">CVE-2008-4315 tog-pegasus: failed authentication attempts not logged via PAM</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081001002" comment="tog-pegasus is earlier than 2:2.7.0-2.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002003" comment="tog-pegasus is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081001004" comment="tog-pegasus-devel is earlier than 2:2.7.0-2.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080002005" comment="tog-pegasus-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081016" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1016: enscript security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1016-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1016.html" />
          <reference source="CVE" ref_id="CVE-2008-3863" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3863.html" />
          <reference source="CVE" ref_id="CVE-2008-4306" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4306.html" />
    
    <description>GNU enscript converts ASCII files to PostScript(R) language files and
spools the generated output to a specified printer or saves it to a file.
Enscript can be extended to handle different output media and includes
options for customizing printouts.

Two buffer overflow flaws were found in GNU enscript. An attacker could
craft an ASCII file in such a way that it could execute arbitrary commands
if the file was opened with enscript with the "special escapes" option (-e
or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306)

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-15" />
        <updated date="2008-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3863.html">CVE-2008-3863</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4306.html">CVE-2008-4306</cve>
                <bugzilla href="http://bugzilla.redhat.com/466771" id="466771">CVE-2008-3863 enscript: "setfilename" special escape buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469311" id="469311">CVE-2008-4306 enscript: "font" special escape buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081016002" comment="enscript is earlier than 0:1.6.4-4.1.1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081016003" comment="enscript is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081017" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:1017: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1017-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1017.html" />
          <reference source="CVE" ref_id="CVE-2008-3831" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3831.html" />
          <reference source="CVE" ref_id="CVE-2008-4554" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4554.html" />
          <reference source="CVE" ref_id="CVE-2008-4576" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4576.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

* Olaf Kirch reported a flaw in the i915 kernel driver. This flaw could,
potentially, lead to local privilege escalation. Note: the flaw only
affects systems based on the Intel G33 Express Chipset and newer.
(CVE-2008-3831, Important)

* Miklos Szeredi reported a missing check for files opened with O_APPEND in
the sys_splice(). This could allow a local, unprivileged user to bypass the
append-only file restrictions. (CVE-2008-4554, Important)

* a deficiency was found in the Linux kernel Stream Control Transmission
Protocol (SCTP) implementation. This could lead to a possible denial of
service if one end of a SCTP connection did not support the AUTH extension.
(CVE-2008-4576, Important)

In addition, these updated packages fix the following bugs:

* on Itanium® systems, when a multithreaded program was traced using the
command "strace -f", messages such as
 
   PANIC: attached pid 10740 exited 
   PANIC: handle_group_exit: 10740 leader 10721
   ...

will be displayed, and after which the trace would stop.  With these
updated packages, "strace -f" command no longer results in these error
messages, and strace terminates normally after tracing all threads.

* on big-endian systems such as PowerPC, the getsockopt() function
incorrectly returned 0 depending on the parameters passed to it when the
time to live (TTL) value equaled 255.

* when using an NFSv4 file system, accessing the same file with two
separate processes simultaneously resulted in the NFS client process
becoming unresponsive.

* on AMD64 and Intel® 64 hypervisor-enabled systems, when a syscall
correctly returned '-1' in code compiled on Red Hat Enterprise Linux 5, the
same code, when run with the strace utility, would incorrectly return an
invalid return value. This has been fixed: on AMD64 and Intel® 64
hypervisor-enabled systems, syscalls in compiled code return the same,
correct values as syscalls run with strace.

* on the Itanium® architecture, fully-virtualized guest domains created
using more than 64 GB of memory caused other guest domains not to receive
interrupts. This caused soft lockups on other guests. All guest domains are
now able to receive interrupts regardless of their allotted memory.

* when user-space used SIGIO notification, which was not disabled before
closing a file descriptor and was then re-enabled in a different process,
an attempt by the kernel to dereference a stale pointer led to a kernel
crash. With this fix, such a situation no longer causes a kernel crash.

* modifications to certain pages made through a memory-mapped region could
have been lost in cases when the NFS client needed to invalidate the page
cache for that particular memory-mapped file.

* fully-virtualized Windows® guests became unresponsive due to the vIOSAPIC
component being multiprocessor-unsafe. With this fix, vIOSAPIC is
multiprocessor-safe and Windows guests do not become unresponsive.

* on certain systems, keyboard controllers could not withstand continuous
requests to switch keyboard LEDs on or off. This resulted in some or all
key presses not being registered by the system.

* on the Itanium® architecture, setting the "vm.nr_hugepages" sysctl
parameter caused a kernel stack overflow resulting in a kernel panic, and
possibly stack corruption. With this fix, setting vm.nr_hugepages works
correctly.

* hugepages allow the Linux kernel to utilize the multiple page size
capabilities of modern hardware architectures. In certain configurations,
systems with large amounts of memory could fail to allocate most of this
memory for hugepages even if it was free. This could result, for example,
in database restart failures.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-16" />
        <updated date="2008-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3831.html">CVE-2008-3831</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4554.html">CVE-2008-4554</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4576.html">CVE-2008-4576</cve>
                <bugzilla href="http://bugzilla.redhat.com/248710" id="248710">Local keyboard DoS through LED switching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450335" id="450335">LTC41974-Pages of a memory mapped NFS file get corrupted.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459080" id="459080">[Xen][5.2.z] softlockup occurs while creating a guest which has large memory.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464502" id="464502">CVE-2008-3831 kernel: i915 kernel drm driver arbitrary ioremap</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465744" id="465744">kernel: rtc: fix kernel panic on second use of SIGIO notification</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466079" id="466079">CVE-2008-4576 kernel: sctp: Fix oops when INIT-ACK indicates that peer doesn't support AUTH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466707" id="466707">CVE-2008-4554 kernel: don't allow splice() to files opened with O_APPEND</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467727" id="467727">[Xen][5.2] Network Performance Test causes Guest Hang.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469150" id="469150">[REG][5.2] The trace of some threads unexpectedly stops when being traced by 'strace -f'.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469649" id="469649">getsockopt() returning incorrectly in PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469650" id="469650">[REG][5.2][NFSv4] Accessing the same file at the same time causes NFSv4 open() call to stall forever on NFS4ERR_DELAY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470853" id="470853">[RHEL5.2]: Running strace with a bad syscall doesn't return -ENOSYS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474347" id="474347">[REG][5.3] Kernel panics when you prepare hugepages.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474760" id="474760">[RHEL5 patch] Allow hugepage allocation to use most of memory.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017004" comment="kernel-headers is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017002" comment="kernel is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017024" comment="kernel-doc is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017020" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017006" comment="kernel-devel is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089009" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017008" comment="kernel-debug is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017018" comment="kernel-kdump is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089017" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017012" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017010" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017022" comment="kernel-PAE is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017016" comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089019" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081017014" comment="kernel-xen is earlier than 0:2.6.18-92.1.22.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080089015" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081018" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1018: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1018.html" />
          <reference source="CVE" ref_id="CVE-2008-2086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2086.html" />
          <reference source="CVE" ref_id="CVE-2008-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5339.html" />
          <reference source="CVE" ref_id="CVE-2008-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5340.html" />
          <reference source="CVE" ref_id="CVE-2008-5341" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5341.html" />
          <reference source="CVE" ref_id="CVE-2008-5342" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5342.html" />
          <reference source="CVE" ref_id="CVE-2008-5343" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5343.html" />
          <reference source="CVE" ref_id="CVE-2008-5344" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5344.html" />
          <reference source="CVE" ref_id="CVE-2008-5345" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5345.html" />
          <reference source="CVE" ref_id="CVE-2008-5347" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5347.html" />
          <reference source="CVE" ref_id="CVE-2008-5348" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5348.html" />
          <reference source="CVE" ref_id="CVE-2008-5349" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5349.html" />
          <reference source="CVE" ref_id="CVE-2008-5350" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5350.html" />
          <reference source="CVE" ref_id="CVE-2008-5351" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5351.html" />
          <reference source="CVE" ref_id="CVE-2008-5352" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5352.html" />
          <reference source="CVE" ref_id="CVE-2008-5353" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5353.html" />
          <reference source="CVE" ref_id="CVE-2008-5354" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5354.html" />
          <reference source="CVE" ref_id="CVE-2008-5356" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5356.html" />
          <reference source="CVE" ref_id="CVE-2008-5357" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5357.html" />
          <reference source="CVE" ref_id="CVE-2008-5358" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5358.html" />
          <reference source="CVE" ref_id="CVE-2008-5359" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5359.html" />
          <reference source="CVE" ref_id="CVE-2008-5360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5360.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language. 

A vulnerability was found in in Java Web Start. If a user visits a
malicious website, an attacker could misuse this flaw to execute arbitrary
code. (CVE-2008-2086)

Additionally, these packages fix several other critical vulnerabilities.
These are summarized in the "Advance notification of Security Updates for
Java SE" from Sun Microsystems.

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-04" />
        <updated date="2008-12-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2086.html">CVE-2008-2086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5339.html">CVE-2008-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5340.html">CVE-2008-5340</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5341.html">CVE-2008-5341</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5342.html">CVE-2008-5342</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5343.html">CVE-2008-5343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5344.html">CVE-2008-5344</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5345.html">CVE-2008-5345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5347.html">CVE-2008-5347</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5348.html">CVE-2008-5348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5349.html">CVE-2008-5349</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5350.html">CVE-2008-5350</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5351.html">CVE-2008-5351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5352.html">CVE-2008-5352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5353.html">CVE-2008-5353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5354.html">CVE-2008-5354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5356.html">CVE-2008-5356</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5357.html">CVE-2008-5357</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5358.html">CVE-2008-5358</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5359.html">CVE-2008-5359</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5360.html">CVE-2008-5360</cve>
                <bugzilla href="http://bugzilla.redhat.com/474556" id="474556">CVE-2008-2086 Java Web Start File Inclusion via System Properties Override</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081018006" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594005" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081018002" comment="java-1.6.0-sun is earlier than 1:1.6.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081018008" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594011" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081018012" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594013" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081018004" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594009" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081018010" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080594007" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081021" version="503" class="patch">
      <metadata>
        <title>RHSA-2008:1021: enscript security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1021-02" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1021.html" />
          <reference source="CVE" ref_id="CVE-2008-3863" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3863.html" />
          <reference source="CVE" ref_id="CVE-2008-4306" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4306.html" />
          <reference source="CVE" ref_id="CVE-2008-5078" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5078.html" />
    
    <description>GNU enscript converts ASCII files to PostScript(R) language files and
spools the generated output to a specified printer or saves it to a file.
Enscript can be extended to handle different output media and includes
options for customizing printouts.

Several buffer overflow flaws were found in GNU enscript. An attacker could
craft an ASCII file in such a way that it could execute arbitrary commands
if the file was opened with enscript with the "special escapes" option (-e
or --escapes) enabled. (CVE-2008-3863, CVE-2008-4306, CVE-2008-5078)

All users of enscript should upgrade to these updated packages, which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-15" />
        <updated date="2008-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3863.html">CVE-2008-3863</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4306.html">CVE-2008-4306</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5078.html">CVE-2008-5078</cve>
                <bugzilla href="http://bugzilla.redhat.com/466771" id="466771">CVE-2008-3863 enscript: "setfilename" special escape buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469311" id="469311">CVE-2008-4306 enscript: "font" special escape buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473958" id="473958">CVE-2008-5078 enscript: "epsf" special escape buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081021002" comment="enscript is earlier than 0:1.6.1-24.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081021003" comment="enscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081021005" comment="enscript is earlier than 0:1.6.1-33.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081021003" comment="enscript is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081023" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1023: pidgin security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1023-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1023.html" />
          <reference source="CVE" ref_id="CVE-2008-2955" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2955.html" />
          <reference source="CVE" ref_id="CVE-2008-2957" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2957.html" />
          <reference source="CVE" ref_id="CVE-2008-3532" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3532.html" />
    
    <description>Pidgin is a multi-protocol Internet Messaging client.

A denial-of-service flaw was found in Pidgin's MSN protocol handler. If a
remote user was able to send, and the Pidgin user accepted, a
carefully-crafted file request, it could result in Pidgin crashing.
(CVE-2008-2955)

A denial-of-service flaw was found in Pidgin's Universal Plug and Play
(UPnP) request handling. A malicious UPnP server could send a request to
Pidgin, causing it to download an excessive amount of data, consuming all
available memory or disk space. (CVE-2008-2957)

A flaw was found in the way Pidgin handled SSL certificates. The NSS SSL
implementation in Pidgin did not properly verify the authenticity of SSL
certificates. This could have resulted in users unknowingly connecting to a
malicious SSL service. (CVE-2008-3532)

In addition, this update upgrades pidgin from version 2.3.1 to version
2.5.2, with many additional stability and functionality fixes from the
Pidgin Project.

Note: the Secure Internet Live Conferencing (SILC) chat network protocol
has recently changed, affecting all versions of pidgin shipped with Red Hat
Enterprise Linux.

Pidgin cannot currently connect to the latest version of the SILC server
(1.1.14): it fails to properly exchange keys during initial login. This
update does not correct this. Red Hat Bugzilla #474212 (linked to in the
References section) has more information.

Note: after the errata packages are installed, Pidgin must be restarted for
the update to take effect.

All Pidgin users should upgrade to these updated packages, which contains
Pidgin version 2.5.2 and resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-15" />
        <updated date="2008-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2955.html">CVE-2008-2955</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2957.html">CVE-2008-2957</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3532.html">CVE-2008-3532</cve>
                <bugzilla href="http://bugzilla.redhat.com/446562" id="446562">User Tune (XEP-0118) shouldn't default on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453736" id="453736">CVE-2008-2955 pidgin: remote DoS via MSN message with crafted file name</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453740" id="453740">CVE-2008-2957 pidgin: unrestricted download of arbitrary files triggered via UPnP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457907" id="457907">CVE-2008-3532 pidgin: NSS plugin doesn't verify SSL certificates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471858" id="471858">Failed to add new MSN group.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472508" id="472508">The Font settings that I customized didn't apply to the outgoing message on the conversation window</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023020" comment="finch is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584011" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023018" comment="libpurple-perl is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584005" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023012" comment="libpurple is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584015" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023002" comment="pidgin is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023004" comment="pidgin-docs is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023005" comment="pidgin-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023014" comment="pidgin-perl is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584017" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023010" comment="pidgin-devel is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023008" comment="libpurple-devel is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584013" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023006" comment="finch-devel is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584009" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023016" comment="libpurple-tcl is earlier than 0:2.5.2-6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584007" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023035" comment="finch is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023036" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023027" comment="libpurple-perl is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023028" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023025" comment="libpurple is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023026" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023023" comment="pidgin is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080584022" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023037" comment="libpurple-devel is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023038" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023033" comment="finch-devel is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023034" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023031" comment="pidgin-perl is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023032" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023029" comment="pidgin-devel is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023030" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081023039" comment="libpurple-tcl is earlier than 0:2.5.2-6.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081023040" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081025" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1025: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1025-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1025.html" />
          <reference source="CVE" ref_id="CVE-2008-2086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2086.html" />
          <reference source="CVE" ref_id="CVE-2008-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5339.html" />
          <reference source="CVE" ref_id="CVE-2008-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5340.html" />
          <reference source="CVE" ref_id="CVE-2008-5341" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5341.html" />
          <reference source="CVE" ref_id="CVE-2008-5342" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5342.html" />
          <reference source="CVE" ref_id="CVE-2008-5343" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5343.html" />
          <reference source="CVE" ref_id="CVE-2008-5344" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5344.html" />
          <reference source="CVE" ref_id="CVE-2008-5345" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5345.html" />
          <reference source="CVE" ref_id="CVE-2008-5346" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5346.html" />
          <reference source="CVE" ref_id="CVE-2008-5348" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5348.html" />
          <reference source="CVE" ref_id="CVE-2008-5349" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5349.html" />
          <reference source="CVE" ref_id="CVE-2008-5350" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5350.html" />
          <reference source="CVE" ref_id="CVE-2008-5351" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5351.html" />
          <reference source="CVE" ref_id="CVE-2008-5352" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5352.html" />
          <reference source="CVE" ref_id="CVE-2008-5353" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5353.html" />
          <reference source="CVE" ref_id="CVE-2008-5354" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5354.html" />
          <reference source="CVE" ref_id="CVE-2008-5356" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5356.html" />
          <reference source="CVE" ref_id="CVE-2008-5357" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5357.html" />
          <reference source="CVE" ref_id="CVE-2008-5359" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5359.html" />
          <reference source="CVE" ref_id="CVE-2008-5360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5360.html" />
    
    <description>The Java Runtime Environment (JRE) contains the software and tools that
users need to run applets and applications written using the Java
programming language. 

A vulnerability was found in in Java Web Start. If a user visits a
malicious website, an attacker could misuse this flaw to execute arbitrary
code. (CVE-2008-2086)

Additionally, these packages fix several other vulnerabilities. These are
summarized in the "Advance notification of Security Updates for Java SE"
from Sun Microsystems. 

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-04" />
        <updated date="2008-12-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2086.html">CVE-2008-2086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5339.html">CVE-2008-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5340.html">CVE-2008-5340</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5341.html">CVE-2008-5341</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5342.html">CVE-2008-5342</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5343.html">CVE-2008-5343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5344.html">CVE-2008-5344</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5345.html">CVE-2008-5345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5346.html">CVE-2008-5346</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5348.html">CVE-2008-5348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5349.html">CVE-2008-5349</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5350.html">CVE-2008-5350</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5351.html">CVE-2008-5351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5352.html">CVE-2008-5352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5353.html">CVE-2008-5353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5354.html">CVE-2008-5354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5356.html">CVE-2008-5356</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5357.html">CVE-2008-5357</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5359.html">CVE-2008-5359</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5360.html">CVE-2008-5360</cve>
                <bugzilla href="http://bugzilla.redhat.com/474556" id="474556">CVE-2008-2086 Java Web Start File Inclusion via System Properties Override</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081025012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081025002" comment="java-1.5.0-sun is earlier than 0:1.5.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081025008" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123011" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081025010" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081025006" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123009" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081025004" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080123005" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081028" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1028: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1028-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1028.html" />
          <reference source="CVE" ref_id="CVE-2008-5286" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5286.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An integer overflow flaw, leading to a heap buffer overflow, was discovered
in the Portable Network Graphics (PNG) decoding routines used by the CUPS
image-converting filters, "imagetops" and "imagetoraster". An attacker
could create a malicious PNG file that could, potentially, execute
arbitrary code as the "lp" user if the file was printed. (CVE-2008-5286)

CUPS users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-15" />
        <updated date="2008-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5286.html">CVE-2008-5286</cve>
                <bugzilla href="http://bugzilla.redhat.com/473905" id="473905">CVE-2008-5286 cups: Incomplete fix for CVE-2008-1722</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081028006" comment="cups-devel is earlier than 1:1.1.17-13.3.55" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153005" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081028004" comment="cups-libs is earlier than 1:1.1.17-13.3.55" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153007" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081028002" comment="cups is earlier than 1:1.1.17-13.3.55" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080153003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081029" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1029: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1029-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1029.html" />
          <reference source="CVE" ref_id="CVE-2008-5183" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5183.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A null pointer dereference flaw was found in the way CUPS handled
subscriptions for printing job completion notifications. A local user could
use this flaw to crash the CUPS daemon by submitting a large number of
printing jobs requiring mail notification on completion, leading to a
denial of service. (CVE-2008-5183)

Users of cups should upgrade to these updated packages, which contain a
backported patch to correct this issue.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-15" />
        <updated date="2008-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5183.html">CVE-2008-5183</cve>
                <bugzilla href="http://bugzilla.redhat.com/473901" id="473901">CVE-2008-5183 cups: DoS (daemon crash) caused by the large number of subscriptions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081029008" comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081029004" comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081029006" comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081029002" comment="cups is earlier than 1:1.2.4-11.18.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080157003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081036" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1036: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1036-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1036.html" />
          <reference source="CVE" ref_id="CVE-2008-5500" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5500.html" />
          <reference source="CVE" ref_id="CVE-2008-5501" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5501.html" />
          <reference source="CVE" ref_id="CVE-2008-5502" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5502.html" />
          <reference source="CVE" ref_id="CVE-2008-5505" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5505.html" />
          <reference source="CVE" ref_id="CVE-2008-5506" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5506.html" />
          <reference source="CVE" ref_id="CVE-2008-5507" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5507.html" />
          <reference source="CVE" ref_id="CVE-2008-5508" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5508.html" />
          <reference source="CVE" ref_id="CVE-2008-5510" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5510.html" />
          <reference source="CVE" ref_id="CVE-2008-5511" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5511.html" />
          <reference source="CVE" ref_id="CVE-2008-5512" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5512.html" />
          <reference source="CVE" ref_id="CVE-2008-5513" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5513.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5511, CVE-2008-5512,
CVE-2008-5513)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could potentially trick a
Firefox user into surrendering sensitive information. (CVE-2008-5506,
CVE-2008-5507)

A flaw was found in the way Firefox stored attributes in XML User Interface
Language (XUL) elements. A web site could use this flaw to track users
across browser sessions, even if users did not allow the site to store
cookies in the victim's browser. (CVE-2008-5505)

A flaw was found in the way malformed URLs were processed by Firefox.
This flaw could prevent various URL sanitization mechanisms from properly
parsing a malicious URL. (CVE-2008-5508)

A flaw was found in Firefox's CSS parser. A malicious web page could inject
NULL characters into a CSS input string, possibly bypassing an
application's script sanitization routines. (CVE-2008-5510)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.5. You can find a link to the Mozilla
advisories in the References section.

Note: after the errata packages are installed, Firefox must be restarted
for the update to take effect.

All firefox users should upgrade to these updated packages, which contain
backported patches that correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-16" />
        <updated date="2008-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5500.html">CVE-2008-5500</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5501.html">CVE-2008-5501</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5502.html">CVE-2008-5502</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5505.html">CVE-2008-5505</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5506.html">CVE-2008-5506</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5507.html">CVE-2008-5507</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5508.html">CVE-2008-5508</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5510.html">CVE-2008-5510</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5511.html">CVE-2008-5511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5512.html">CVE-2008-5512</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5513.html">CVE-2008-5513</cve>
                <bugzilla href="http://bugzilla.redhat.com/476266" id="476266">CVE-2008-5500 Layout engine crashes - Firefox 2 and 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476267" id="476267">CVE-2008-5501 Layout engine crash - Firefox 3 only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476269" id="476269">CVE-2008-5502 JavaScript engine crash - Firefox 3 only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476274" id="476274">CVE-2008-5505 Firefox 3 User tracking via XUL persist attribute</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476278" id="476278">CVE-2008-5506 Firefox XMLHttpRequest 302 response disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476280" id="476280">CVE-2008-5507 Firefox Cross-domain data theft via script redirect error message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476281" id="476281">CVE-2008-5508 Firefox errors parsing URLs with control characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476283" id="476283">CVE-2008-5510 Firefox null characters ignored by CSS parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476285" id="476285">CVE-2008-5511 Firefox XSS via XBL bindings to unloaded document</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476287" id="476287">CVE-2008-5512 Firefox JavaScript privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476289" id="476289">CVE-2008-5513 Firefox XSS vulnerabilities in SessionStore</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036002" comment="firefox is earlier than 0:3.0.5-1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103003" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036008" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.5-1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569007" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036004" comment="xulrunner is earlier than 0:1.9.0.5-1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036006" comment="xulrunner-devel is earlier than 0:1.9.0.5-1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080569005" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036012" comment="nspr-devel is earlier than 0:4.7.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081036013" comment="nspr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036010" comment="nspr is earlier than 0:4.7.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081036011" comment="nspr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036014" comment="nss is earlier than 0:3.12.2.0-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879009" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036018" comment="nss-tools is earlier than 0:3.12.2.0-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879015" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036020" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879011" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036016" comment="nss-devel is earlier than 0:3.12.2.0-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080879013" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036023" comment="firefox is earlier than 0:3.0.5-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080103008" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036025" comment="nss is earlier than 0:3.12.2.0-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080978028" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036027" comment="nss-devel is earlier than 0:3.12.2.0-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080978030" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036031" comment="nspr-devel is earlier than 0:4.7.3-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081036032" comment="nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081036029" comment="nspr is earlier than 0:4.7.3-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081036030" comment="nspr is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081037" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1037: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1037-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1037.html" />
          <reference source="CVE" ref_id="CVE-2008-5500" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5500.html" />
          <reference source="CVE" ref_id="CVE-2008-5501" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5501.html" />
          <reference source="CVE" ref_id="CVE-2008-5502" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5502.html" />
          <reference source="CVE" ref_id="CVE-2008-5503" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5503.html" />
          <reference source="CVE" ref_id="CVE-2008-5504" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5504.html" />
          <reference source="CVE" ref_id="CVE-2008-5506" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5506.html" />
          <reference source="CVE" ref_id="CVE-2008-5507" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5507.html" />
          <reference source="CVE" ref_id="CVE-2008-5508" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5508.html" />
          <reference source="CVE" ref_id="CVE-2008-5511" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5511.html" />
          <reference source="CVE" ref_id="CVE-2008-5512" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5512.html" />
          <reference source="CVE" ref_id="CVE-2008-5513" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5513.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5504, CVE-2008-5511,
CVE-2008-5512, CVE-2008-5513)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could potentially trick a
SeaMonkey user into surrendering sensitive information. (CVE-2008-5503,
CVE-2008-5506, CVE-2008-5507)

A flaw was found in the way malformed URLs were processed by SeaMonkey.
This flaw could prevent various URL sanitization mechanisms from properly
parsing a malicious URL. (CVE-2008-5508)

Note: after the errata packages are installed, SeaMonkey must be restarted
for the update to take effect.

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-16" />
        <updated date="2008-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5500.html">CVE-2008-5500</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5501.html">CVE-2008-5501</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5502.html">CVE-2008-5502</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5503.html">CVE-2008-5503</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5504.html">CVE-2008-5504</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5506.html">CVE-2008-5506</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5507.html">CVE-2008-5507</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5508.html">CVE-2008-5508</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5511.html">CVE-2008-5511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5512.html">CVE-2008-5512</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5513.html">CVE-2008-5513</cve>
                <bugzilla href="http://bugzilla.redhat.com/476266" id="476266">CVE-2008-5500 Layout engine crashes - Firefox 2 and 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476267" id="476267">CVE-2008-5501 Layout engine crash - Firefox 3 only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476269" id="476269">CVE-2008-5502 JavaScript engine crash - Firefox 3 only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476272" id="476272">CVE-2008-5503 Firefox 2  Information stealing via loadBindingDocument</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476273" id="476273">CVE-2008-5504 Firefox 2 XSS attack vectors in feed preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476278" id="476278">CVE-2008-5506 Firefox XMLHttpRequest 302 response disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476280" id="476280">CVE-2008-5507 Firefox Cross-domain data theft via script redirect error message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476281" id="476281">CVE-2008-5508 Firefox errors parsing URLs with control characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476285" id="476285">CVE-2008-5511 Firefox XSS via XBL bindings to unloaded document</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476287" id="476287">CVE-2008-5512 Firefox JavaScript privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476289" id="476289">CVE-2008-5513 Firefox XSS vulnerabilities in SessionStore</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080003008" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037016" comment="seamonkey-nspr is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104007" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037020" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104009" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037006" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037004" comment="seamonkey-mail is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037002" comment="seamonkey is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037014" comment="seamonkey-devel is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037012" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104005" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037010" comment="seamonkey-nss is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037008" comment="seamonkey-chat is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037018" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.29.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002006" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037024" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-32.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104011" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037025" comment="seamonkey-mail is earlier than 0:1.0.9-32.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104019" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037023" comment="seamonkey is earlier than 0:1.0.9-32.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037028" comment="seamonkey-devel is earlier than 0:1.0.9-32.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104017" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037027" comment="seamonkey-chat is earlier than 0:1.0.9-32.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104013" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081037026" comment="seamonkey-js-debugger is earlier than 0:1.0.9-32.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080104021" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081043" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1043: java-1.4.2-bea security update (Important)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1043-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1043.html" />
    
    <description>The BEA WebLogic JRockit JRE and SDK contains BEA WebLogic JRockit Virtual
Machine and is certified for the Java™ 2 Platform, Standard Edition,
v1.4.2.

The java-1.4.2-bea packages are vulnerable to important security flaws and
should no longer be used.

Several flaws involving the handling of unsigned applets were found. A
remote attacker could misuse an unsigned applet in order to connect to
services on the host running the applet. (CVE-2008-3104)

A buffer overflow vulnerability was found in the font processing code. This
allowed remote attackers to extend the permissions of an untrusted applet
or application, allowing it to read or write local files, as well as to
execute local applications accessible to the user running the untrusted
application. (CVE-2008-3108)

The vulnerabilities concerning applets listed above can only be triggered
in java-1.4.2-bea by calling the "appletviewer" application.

BEA was acquired by Oracle® during 2008 (the acquisition was completed on
April 29, 2008). Consequently, JRockit is now an Oracle offering and these
issues are addressed in the current release of Oracle JRockit. Due to a
license change by Oracle, however, Red Hat is unable to ship Oracle
JRockit.

Users who wish to continue using JRockit should get an update directly from
Oracle: http://oracle.com/technology/software/products/jrockit/.

Alternatives to Oracle JRockit include the Java 2 Technology Edition of the
IBM® Developer Kit for Linux and the Sun™ Java SE Development Kit (JDK),
both of which are available on the Extras or Supplementary channels. For
Java 6 users, the new OpenJDK open source JDK will be included in Red Hat
Enterprise Linux 5.3 and will be supported by Red Hat.

This update removes the java-1.4.2-bea packages due to their known security
vulnerabilities.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-18" />
        <updated date="2008-12-18" />
                <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454604" id="454604">CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081043004" comment="java-1.4.2-bea-uninstall is earlier than 0:1.4.2.16-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081043005" comment="java-1.4.2-bea-uninstall is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081043002" comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080100003" comment="java-1.4.2-bea is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081044" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1044: java-1.5.0-bea security update (Important)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1044-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1044.html" />
    
    <description>The BEA WebLogic JRockit JRE and SDK contains BEA WebLogic JRockit Virtual
Machine and is certified for the Java™ 2 Platform, Standard Edition,
v1.5.0.

The java-1.5.0-bea packages are vulnerable to important security flaws and
should no longer be used.

A flaw was found in the Java Management Extensions (JMX) management agent.
When local monitoring was enabled, remote attackers could use this flaw to
perform illegal operations. (CVE-2008-3103)

Several flaws involving the handling of unsigned applets were found. A
remote attacker could misuse an unsigned applet in order to connect to
services on the host running the applet. (CVE-2008-3104)

Several flaws in the Java API for XML Web Services (JAX-WS) client and the
JAX-WS service implementation were found. A remote attacker who could cause
malicious XML to be processed by an application could access URLs, or cause
a denial of service. (CVE-2008-3105, CVE-2008-3106)

A buffer overflow vulnerability was found in the font processing code. This
allowed remote attackers to extend the permissions of an untrusted applet
or application, allowing it to read or write local files, as well as to
execute local applications accessible to the user running the untrusted
application. (CVE-2008-3108)

The vulnerabilities concerning applets listed above can only be triggered
in java-1.5.0-bea, by calling the "appletviewer" application.

BEA was acquired by Oracle® during 2008 (the acquisition was completed on
April 29, 2008). Consequently, JRockit is now an Oracle offering and these
issues are addressed in the current release of Oracle JRockit. Due to a
license change by Oracle, however, Red Hat is unable to ship Oracle
JRockit.

Users who wish to continue using JRockit should get an update directly from
Oracle: http://oracle.com/technology/software/products/jrockit/.

Alternatives to Oracle JRockit include the Java 2 Technology Edition of the
IBM® Developer Kit for Linux and the Sun™ Java SE Development Kit (JDK),
both of which are available on the Extras or Supplementary channels. For
Java 6 users, the new OpenJDK open source JDK will be included in Red Hat
Enterprise Linux 5.3 and will be supported by Red Hat.

This update removes the java-1.5.0-bea packages due to their known security
vulnerabilities.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-18" />
        <updated date="2008-12-18" />
                <bugzilla href="http://bugzilla.redhat.com/452649" id="452649">CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452659" id="452659">CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454604" id="454604">CVE-2008-3108 Security Vulnerability with JRE fonts processing may allow Elevation of Privileges (6450319)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081044002" comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080156003" comment="java-1.5.0-bea is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081044004" comment="java-1.5.0-bea-uninstall is earlier than 0:1.5.0.14-1jpp.5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081044005" comment="java-1.5.0-bea-uninstall is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081045" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1045: java-1.6.0-bea security update (Important)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1045-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1045.html" />
    
    <description>The BEA WebLogic JRockit JRE and SDK contains BEA WebLogic JRockit Virtual
Machine and is certified for the Java™ 2 Platform, Standard Edition,
v1.6.0.

The java-1.6.0-bea packages are vulnerable to important security flaws and
should no longer be used.

A flaw was found in the Java Management Extensions (JMX) management agent.
When local monitoring was enabled, remote attackers could use this flaw to
perform illegal operations. (CVE-2008-3103)

Several flaws involving the handling of unsigned applets were found. A
remote attacker could misuse an unsigned applet in order to connect to
services on the host running the applet. (CVE-2008-3104)

Several flaws in the Java API for XML Web Services (JAX-WS) client and the
JAX-WS service implementation were found. A remote attacker who could cause
malicious XML to be processed by an application could access URLs, or cause
a denial of service. (CVE-2008-3105, CVE-2008-3106)

Several flaws within the Java Runtime Environment's (JRE) scripting support
were found. A remote attacker could grant an untrusted applet extended
privileges, such as reading and writing local files, executing local
programs, or querying the sensitive data of other applets. (CVE-2008-3109,
CVE-2008-3110)

The vulnerabilities concerning applets listed above can only be triggered
in java-1.6.0-bea, by calling the "appletviewer" application.

BEA was acquired by Oracle® during 2008 (the acquisition was completed on
April 29, 2008). Consequently, JRockit is now an Oracle offering and these
issues are addressed in the current release of Oracle JRockit. Due to a
license change by Oracle, however, Red Hat is unable to ship Oracle
JRockit.

Users who wish to continue using JRockit should get an update directly from
Oracle: http://oracle.com/technology/software/products/jrockit/.

Alternatives to Oracle JRockit include the Java 2 Technology Edition of the
IBM® Developer Kit for Linux and the Sun™ Java SE Development Kit (JDK),
both of which are available on the Extras or Supplementary channels. For
Java 6 users, the new OpenJDK open source JDK will be included in Red Hat
Enterprise Linux 5.3 and will be supported by Red Hat.

This update removes the java-1.6.0-bea packages due to their known security
vulnerabilities.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-18" />
        <updated date="2008-12-18" />
                <bugzilla href="http://bugzilla.redhat.com/452649" id="452649">CVE-2008-3105 CVE-2008-3106 OpenJDK JAX-WS unauthorized URL access (6542088)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452659" id="452659">CVE-2008-3103 OpenJDK JMX allows illegal operations with local monitoring (6332953)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454601" id="454601">CVE-2008-3104 Java RE allows Same Origin Policy to be Bypassed (6687932)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454603" id="454603">CVE-2008-3109 CVE-2008-3110 Security Vulnerabilities in the Java Runtime Environment Scripting Language Support (6529568, 6529579)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081045004" comment="java-1.6.0-bea-uninstall is earlier than 1:1.6.0.03-1jpp.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081045005" comment="java-1.6.0-bea-uninstall is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20081045002" comment="java-1.6.0-bea is earlier than 1:1.6.0.03-1jpp.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080245003" comment="java-1.6.0-bea is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20081047" version="502" class="patch">
      <metadata>
        <title>RHSA-2008:1047: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2008:1047-01" ref_url="https://rhn.redhat.com/errata/RHSA-2008-1047.html" />
          <reference source="CVE" ref_id="CVE-2008-5499" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5499.html" />
    
    <description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
Web browser plug-in.

A security flaw was found in the way Flash Player displayed certain SWF
(Shockwave Flash) content. This may have made it possible to execute
arbitrary code on a victim's machine, if the victim opened a malicious
Adobe Flash file. (CVE-2008-5499)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.0.15.3 for users of Red Hat Enterprise
Linux 5 Supplementary, and 9.0.152.0 for users of Red Hat Enterprise 3 and
4 Extras.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2008 Red Hat, Inc.</rights>
        <issued date="2008-12-19" />
        <updated date="2008-12-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5499.html">CVE-2008-5499</cve>
                <bugzilla href="http://bugzilla.redhat.com/476172" id="476172">CVE-2008-5499 flash-plugin: Linux-specific code execution flaw via crafted SWF file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20080002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20081047002" comment="flash-plugin is earlier than 0:10.0.15.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20080221003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
</definitions>

<tests>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002001" version="502" comment="Red Hat Enterprise Linux 5 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002002" version="502" comment="tog-pegasus is earlier than 2:2.6.1-2.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002003" version="502" comment="tog-pegasus is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002004" version="502" comment="tog-pegasus-devel is earlier than 2:2.6.1-2.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002005" version="502" comment="tog-pegasus-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002006" version="502" comment="Red Hat Enterprise Linux 4 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002007" version="502" comment="tog-pegasus is earlier than 2:2.5.1-5.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002008" version="502" comment="tog-pegasus is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002009" version="502" comment="tog-pegasus-test is earlier than 2:2.5.1-5.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002010" version="502" comment="tog-pegasus-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002011" version="502" comment="tog-pegasus-devel is earlier than 2:2.5.1-5.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080002012" version="502" comment="tog-pegasus-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003002" version="502" comment="e2fsprogs is earlier than 0:1.39-10.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003003" version="502" comment="e2fsprogs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003004" version="502" comment="e2fsprogs-libs is earlier than 0:1.39-10.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003005" version="502" comment="e2fsprogs-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003006" version="502" comment="e2fsprogs-devel is earlier than 0:1.39-10.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003007" version="502" comment="e2fsprogs-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003008" version="502" comment="Red Hat Enterprise Linux 3 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080002001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003009" version="502" comment="e2fsprogs is earlier than 0:1.32-15.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003010" version="502" comment="e2fsprogs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003011" version="502" comment="e2fsprogs-devel is earlier than 0:1.32-15.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003012" version="502" comment="e2fsprogs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003014" version="502" comment="e2fsprogs is earlier than 0:1.35-12.11.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080003015" version="502" comment="e2fsprogs-devel is earlier than 0:1.35-12.11.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080003008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080005002" version="502" comment="httpd is earlier than 0:2.0.46-70.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080005003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080005003" version="502" comment="httpd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080005004" version="502" comment="mod_ssl is earlier than 0:2.0.46-70.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080005003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080005005" version="502" comment="mod_ssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080005006" version="502" comment="httpd-devel is earlier than 0:2.0.46-70.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080005003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080005007" version="502" comment="httpd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006002" version="502" comment="httpd is earlier than 0:2.0.52-38.ent.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080006003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006004" version="502" comment="mod_ssl is earlier than 0:2.0.52-38.ent.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080006003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006006" version="502" comment="httpd-devel is earlier than 0:2.0.52-38.ent.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080006003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006008" version="502" comment="httpd-suexec is earlier than 0:2.0.52-38.ent.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080006005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080006003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006009" version="502" comment="httpd-suexec is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080006005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006010" version="502" comment="httpd-manual is earlier than 0:2.0.52-38.ent.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080006006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080006003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080006011" version="502" comment="httpd-manual is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080006006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008002" version="502" comment="httpd is earlier than 0:2.2.3-11.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008003" version="502" comment="httpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008004" version="502" comment="httpd-devel is earlier than 0:2.2.3-11.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008005" version="502" comment="httpd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008006" version="502" comment="httpd-manual is earlier than 0:2.2.3-11.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080006006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008007" version="502" comment="httpd-manual is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080006006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008008" version="502" comment="mod_ssl is earlier than 0:2.2.3-11.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080008009" version="502" comment="mod_ssl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029002" version="503" comment="XFree86 is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029003" version="503" comment="XFree86 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029004" version="503" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029005" version="503" comment="XFree86-ISO8859-15-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029006" version="503" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029007" version="503" comment="XFree86-ISO8859-2-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029008" version="503" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029009" version="503" comment="XFree86-ISO8859-9-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029010" version="503" comment="XFree86-xfs is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029011" version="503" comment="XFree86-xfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029012" version="503" comment="XFree86-devel is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029013" version="503" comment="XFree86-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029014" version="503" comment="XFree86-Xnest is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029015" version="503" comment="XFree86-Xnest is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029016" version="503" comment="XFree86-tools is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029017" version="503" comment="XFree86-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029018" version="503" comment="XFree86-sdk is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029019" version="503" comment="XFree86-sdk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029020" version="503" comment="XFree86-xauth is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029021" version="503" comment="XFree86-xauth is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029022" version="503" comment="XFree86-xdm is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029023" version="503" comment="XFree86-xdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029024" version="503" comment="XFree86-libs-data is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029025" version="503" comment="XFree86-libs-data is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029026" version="503" comment="XFree86-twm is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029027" version="503" comment="XFree86-twm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029028" version="503" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029029" version="503" comment="XFree86-syriac-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029030" version="503" comment="XFree86-base-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029031" version="503" comment="XFree86-base-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029032" version="503" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029033" version="503" comment="XFree86-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029034" version="503" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029035" version="503" comment="XFree86-ISO8859-2-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029036" version="503" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029037" version="503" comment="XFree86-ISO8859-14-75dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029038" version="503" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029039" version="503" comment="XFree86-cyrillic-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029040" version="503" comment="XFree86-Xvfb is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029041" version="503" comment="XFree86-Xvfb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029042" version="503" comment="XFree86-doc is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029043" version="503" comment="XFree86-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029044" version="503" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029045" version="503" comment="XFree86-Mesa-libGLU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029046" version="503" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029047" version="503" comment="XFree86-truetype-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029048" version="503" comment="XFree86-font-utils is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029049" version="503" comment="XFree86-font-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029050" version="503" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029051" version="503" comment="XFree86-ISO8859-9-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029052" version="503" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029053" version="503" comment="XFree86-ISO8859-15-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029054" version="503" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029055" version="503" comment="XFree86-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029056" version="503" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029057" version="503" comment="XFree86-Mesa-libGL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029058" version="503" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029059" version="503" comment="XFree86-ISO8859-14-100dpi-fonts is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029060" version="503" comment="XFree86-libs is earlier than 0:4.3.0-126.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080029003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080029061" version="503" comment="XFree86-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030002" version="503" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030003" version="503" comment="xorg-x11 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030004" version="503" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030005" version="503" comment="xorg-x11-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030006" version="503" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030007" version="503" comment="xorg-x11-Xvfb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030008" version="503" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030009" version="503" comment="xorg-x11-Mesa-libGL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030010" version="503" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030011" version="503" comment="xorg-x11-deprecated-libs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030012" version="503" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030013" version="503" comment="xorg-x11-xauth is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030014" version="503" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030015" version="503" comment="xorg-x11-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030016" version="503" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030017" version="503" comment="xorg-x11-xfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030018" version="503" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030019" version="503" comment="xorg-x11-twm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030020" version="503" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030021" version="503" comment="xorg-x11-Xnest is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030022" version="503" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030023" version="503" comment="xorg-x11-Mesa-libGLU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030024" version="503" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030025" version="503" comment="xorg-x11-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030026" version="503" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030027" version="503" comment="xorg-x11-Xdmx is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030028" version="503" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030029" version="503" comment="xorg-x11-sdk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030030" version="503" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030031" version="503" comment="xorg-x11-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030032" version="503" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030033" version="503" comment="xorg-x11-font-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030034" version="503" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030035" version="503" comment="xorg-x11-deprecated-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030036" version="503" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080030003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080030037" version="503" comment="xorg-x11-xdm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031002" version="503" comment="xorg-x11-server is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031003" version="503" comment="xorg-x11-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031004" version="503" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031005" version="503" comment="xorg-x11-server-Xephyr is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031006" version="503" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031007" version="503" comment="xorg-x11-server-Xnest is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031008" version="503" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031009" version="503" comment="xorg-x11-server-Xvfb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031010" version="503" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031011" version="503" comment="xorg-x11-server-Xdmx is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031012" version="503" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031013" version="503" comment="xorg-x11-server-sdk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031014" version="503" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.26.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080031003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080031015" version="503" comment="xorg-x11-server-Xorg is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032002" version="502" comment="libxml2 is earlier than 0:2.6.26-2.1.2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032003" version="502" comment="libxml2 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032004" version="502" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032005" version="502" comment="libxml2-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032006" version="502" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032007" version="502" comment="libxml2-python is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032009" version="502" comment="libxml2 is earlier than 0:2.5.10-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032010" version="502" comment="libxml2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032011" version="502" comment="libxml2-devel is earlier than 0:2.5.10-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032012" version="502" comment="libxml2-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032013" version="502" comment="libxml2-python is earlier than 0:2.5.10-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032014" version="502" comment="libxml2-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032016" version="502" comment="libxml2 is earlier than 0:2.6.16-10.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032017" version="502" comment="libxml2-devel is earlier than 0:2.6.16-10.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080032018" version="502" comment="libxml2-python is earlier than 0:2.6.16-10.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080032004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080032008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038002" version="502" comment="postgresql is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038003" version="502" comment="postgresql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038004" version="502" comment="postgresql-devel is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038005" version="502" comment="postgresql-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038006" version="502" comment="postgresql-server is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038007" version="502" comment="postgresql-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038008" version="502" comment="postgresql-libs is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038009" version="502" comment="postgresql-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038010" version="502" comment="postgresql-python is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038011" version="502" comment="postgresql-python is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038012" version="502" comment="postgresql-tcl is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038013" version="502" comment="postgresql-tcl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038014" version="502" comment="postgresql-pl is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038015" version="502" comment="postgresql-pl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038016" version="502" comment="postgresql-test is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038017" version="502" comment="postgresql-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038018" version="502" comment="postgresql-docs is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038019" version="502" comment="postgresql-docs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038020" version="502" comment="postgresql-contrib is earlier than 0:8.1.11-1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038021" version="502" comment="postgresql-contrib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038023" version="502" comment="postgresql is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038024" version="502" comment="postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038025" version="502" comment="postgresql-devel is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038026" version="502" comment="postgresql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038027" version="502" comment="postgresql-pl is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038028" version="502" comment="postgresql-pl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038029" version="502" comment="postgresql-docs is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038030" version="502" comment="postgresql-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038031" version="502" comment="postgresql-contrib is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038032" version="502" comment="postgresql-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038033" version="502" comment="postgresql-server is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038034" version="502" comment="postgresql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038035" version="502" comment="postgresql-jdbc is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038036" version="502" comment="postgresql-jdbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038037" version="502" comment="postgresql-python is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038038" version="502" comment="postgresql-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038039" version="502" comment="postgresql-test is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038040" version="502" comment="postgresql-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038041" version="502" comment="postgresql-libs is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038042" version="502" comment="postgresql-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038043" version="502" comment="postgresql-tcl is earlier than 0:7.4.19-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080038006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080038044" version="502" comment="postgresql-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080038007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039002" version="502" comment="rh-postgresql is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039003" version="502" comment="rh-postgresql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039004" version="502" comment="rh-postgresql-jdbc is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039005" version="502" comment="rh-postgresql-jdbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039006" version="502" comment="rh-postgresql-python is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039007" version="502" comment="rh-postgresql-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039008" version="502" comment="rh-postgresql-server is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039009" version="502" comment="rh-postgresql-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039010" version="502" comment="rh-postgresql-contrib is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039011" version="502" comment="rh-postgresql-contrib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039012" version="502" comment="rh-postgresql-test is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039013" version="502" comment="rh-postgresql-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039014" version="502" comment="rh-postgresql-pl is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039015" version="502" comment="rh-postgresql-pl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039016" version="502" comment="rh-postgresql-devel is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039017" version="502" comment="rh-postgresql-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039018" version="502" comment="rh-postgresql-docs is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039019" version="502" comment="rh-postgresql-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039020" version="502" comment="rh-postgresql-tcl is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039021" version="502" comment="rh-postgresql-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039022" version="502" comment="rh-postgresql-libs is earlier than 0:7.3.21-1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080039023" version="502" comment="rh-postgresql-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080039012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042002" version="502" comment="tomcat5 is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042003" version="502" comment="tomcat5 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042004" version="502" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042005" version="502" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042006" version="502" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042007" version="502" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042008" version="502" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042009" version="502" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042010" version="502" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042011" version="502" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042012" version="502" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042013" version="502" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042014" version="502" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042015" version="502" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042016" version="502" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042017" version="502" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042018" version="502" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042019" version="502" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042020" version="502" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042021" version="502" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042022" version="502" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.3.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080042003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080042023" version="502" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080042012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055002" version="502" comment="kernel is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055003" version="502" comment="kernel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055004" version="502" comment="kernel-devel is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055005" version="502" comment="kernel-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055006" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055007" version="502" comment="kernel-smp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055008" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055009" version="502" comment="kernel-largesmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055010" version="502" comment="kernel-xenU is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055011" version="502" comment="kernel-xenU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055012" version="502" comment="kernel-smp is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055013" version="502" comment="kernel-smp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055014" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055015" version="502" comment="kernel-largesmp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055016" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055017" version="502" comment="kernel-xenU-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055019" version="502" comment="kernel-hugemem-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055021" version="502" comment="kernel-hugemem is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055022" version="502" comment="kernel-doc is earlier than 0:2.6.9-67.0.4.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080055003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080055023" version="502" comment="kernel-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058002" version="502" comment="wireshark is earlier than 0:0.99.7-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058003" version="502" comment="wireshark is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058004" version="502" comment="wireshark-gnome is earlier than 0:0.99.7-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058005" version="502" comment="wireshark-gnome is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058006" version="502" comment="libsmi is earlier than 0:0.4.5-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058007" version="502" comment="libsmi is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058008" version="502" comment="libsmi-devel is earlier than 0:0.4.5-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058009" version="502" comment="libsmi-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058011" version="502" comment="wireshark is earlier than 0:0.99.7-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058012" version="502" comment="wireshark is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058013" version="502" comment="wireshark-gnome is earlier than 0:0.99.7-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058014" version="502" comment="wireshark-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058015" version="502" comment="libsmi is earlier than 0:0.4.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058016" version="502" comment="libsmi is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058017" version="502" comment="libsmi-devel is earlier than 0:0.4.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080058008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080058018" version="502" comment="libsmi-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080059002" version="502" comment="libsmi is earlier than 0:0.4.5-3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080059003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080059004" version="502" comment="libsmi-devel is earlier than 0:0.4.5-3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080059003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080059006" version="502" comment="wireshark is earlier than 0:0.99.7-EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080059004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080059008" version="502" comment="wireshark-gnome is earlier than 0:0.99.7-EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080058003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080059004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080061002" version="503" comment="setroubleshoot-plugins is earlier than 0:2.0.4-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080061002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080061003" version="503" comment="setroubleshoot-plugins is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080061002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080061004" version="503" comment="setroubleshoot is earlier than 0:2.0.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080061003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080061004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080061005" version="503" comment="setroubleshoot is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080061003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080061006" version="503" comment="setroubleshoot-server is earlier than 0:2.0.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080061004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080061004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080061007" version="503" comment="setroubleshoot-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080061004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080064002" version="502" comment="libXfont is earlier than 0:1.2.2-1.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080064002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080064003" version="502" comment="libXfont is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080064002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080064004" version="502" comment="libXfont-devel is earlier than 0:1.2.2-1.0.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080064003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080064003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080064005" version="502" comment="libXfont-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080064003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089002" version="502" comment="kernel is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089003" version="502" comment="kernel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089004" version="502" comment="kernel-headers is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089005" version="502" comment="kernel-headers is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089006" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089007" version="502" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089008" version="502" comment="kernel-devel is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089009" version="502" comment="kernel-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089010" version="502" comment="kernel-debug is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089011" version="502" comment="kernel-debug is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089012" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089013" version="502" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089014" version="502" comment="kernel-xen is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089015" version="502" comment="kernel-xen is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089016" version="502" comment="kernel-kdump is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089017" version="502" comment="kernel-kdump is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089018" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089019" version="502" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089021" version="502" comment="kernel-PAE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089023" version="502" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089024" version="502" comment="kernel-doc is earlier than 0:2.6.18-53.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080089003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080089025" version="502" comment="kernel-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090002" version="502" comment="icu is earlier than 0:3.6-5.11.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080090003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090003" version="502" comment="icu is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090004" version="502" comment="libicu-doc is earlier than 0:3.6-5.11.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080090003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090005" version="502" comment="libicu-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090006" version="502" comment="libicu-devel is earlier than 0:3.6-5.11.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080090003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090007" version="502" comment="libicu-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090008" version="502" comment="libicu is earlier than 0:3.6-5.11.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080090003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080090009" version="502" comment="libicu is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080090005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100002" version="502" comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100003" version="502" comment="java-1.4.2-bea is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100004" version="502" comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100005" version="502" comment="java-1.4.2-bea-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100006" version="502" comment="java-1.4.2-bea-src is earlier than 0:1.4.2.16-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100007" version="502" comment="java-1.4.2-bea-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100008" version="502" comment="java-1.4.2-bea-demo is earlier than 0:1.4.2.16-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100009" version="502" comment="java-1.4.2-bea-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100010" version="502" comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100011" version="502" comment="java-1.4.2-bea-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100012" version="502" comment="java-1.4.2-bea-missioncontrol is earlier than 0:1.4.2.16-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080100013" version="502" comment="java-1.4.2-bea-missioncontrol is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080103002" version="502" comment="firefox is earlier than 0:1.5.0.12-9.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080103004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080103003" version="502" comment="firefox is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080103004" version="502" comment="firefox-devel is earlier than 0:1.5.0.12-9.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080103004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080103005" version="502" comment="firefox-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080103007" version="502" comment="firefox is earlier than 0:1.5.0.12-0.10.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080103006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080103008" version="502" comment="firefox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104003" version="502" comment="seamonkey is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104004" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104005" version="502" comment="seamonkey-nss-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104006" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104007" version="502" comment="seamonkey-nspr is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104008" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104009" version="502" comment="seamonkey-nspr-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104010" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104011" version="502" comment="seamonkey-dom-inspector is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104012" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104013" version="502" comment="seamonkey-chat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104014" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104015" version="502" comment="seamonkey-nss is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104016" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104017" version="502" comment="seamonkey-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104018" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104019" version="502" comment="seamonkey-mail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104020" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104021" version="502" comment="seamonkey-js-debugger is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104023" version="502" comment="seamonkey is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104024" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104025" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104026" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104027" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104028" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104029" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104030" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104031" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080104032" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-9.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080104005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080105002" version="503" comment="thunderbird is earlier than 0:1.5.0.12-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080105004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080105003" version="503" comment="thunderbird is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080105005" version="503" comment="thunderbird is earlier than 0:1.5.0.12-8.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080105006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080105006" version="503" comment="thunderbird is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110002" version="502" comment="openldap is earlier than 0:2.3.27-8.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110003" version="502" comment="openldap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110004" version="502" comment="openldap-clients is earlier than 0:2.3.27-8.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110005" version="502" comment="openldap-clients is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110006" version="502" comment="openldap-servers-sql is earlier than 0:2.3.27-8.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110007" version="502" comment="openldap-servers-sql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110008" version="502" comment="compat-openldap is earlier than 0:2.3.27_2.2.29-8.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110009" version="502" comment="compat-openldap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110010" version="502" comment="openldap-devel is earlier than 0:2.3.27-8.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110011" version="502" comment="openldap-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110012" version="502" comment="openldap-servers is earlier than 0:2.3.27-8.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110013" version="502" comment="openldap-servers is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110015" version="502" comment="openldap is earlier than 0:2.2.13-8.el4_6.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110016" version="502" comment="openldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110017" version="502" comment="compat-openldap is earlier than 0:2.1.30-8.el4_6.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110018" version="502" comment="compat-openldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110019" version="502" comment="openldap-clients is earlier than 0:2.2.13-8.el4_6.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110020" version="502" comment="openldap-clients is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110021" version="502" comment="openldap-servers-sql is earlier than 0:2.2.13-8.el4_6.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110022" version="502" comment="openldap-servers-sql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110023" version="502" comment="openldap-devel is earlier than 0:2.2.13-8.el4_6.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110024" version="502" comment="openldap-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110025" version="502" comment="openldap-servers is earlier than 0:2.2.13-8.el4_6.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080110007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080110026" version="502" comment="openldap-servers is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123002" version="502" comment="java-1.5.0-sun is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123003" version="502" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123004" version="502" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123005" version="502" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123006" version="502" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123007" version="502" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123008" version="502" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123009" version="502" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123010" version="502" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123011" version="502" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123012" version="502" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080123013" version="502" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129002" version="502" comment="kernel is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129004" version="502" comment="kernel-headers is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129006" version="502" comment="kernel-devel is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129008" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129010" version="502" comment="kernel-xen is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129012" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129014" version="502" comment="kernel-debug is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129016" version="502" comment="kernel-kdump is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129018" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080129024" version="502" comment="kernel-doc is earlier than 0:2.6.18-53.1.13.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080129003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131002" version="502" comment="netpbm is earlier than 0:9.24-11.30.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080131003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131003" version="502" comment="netpbm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131004" version="502" comment="netpbm-devel is earlier than 0:9.24-11.30.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080131003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131005" version="502" comment="netpbm-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131006" version="502" comment="netpbm-progs is earlier than 0:9.24-11.30.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080131003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131007" version="502" comment="netpbm-progs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131009" version="502" comment="netpbm is earlier than 0:10.25-2.EL4.6.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080131005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131010" version="502" comment="netpbm-devel is earlier than 0:10.25-2.EL4.6.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080131005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080131011" version="502" comment="netpbm-progs is earlier than 0:10.25-2.EL4.6.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080131004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080131005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132002" version="502" comment="java-1.4.2-ibm is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132003" version="502" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132004" version="502" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132005" version="502" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132006" version="502" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132007" version="502" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132008" version="502" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132009" version="502" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132010" version="502" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132011" version="502" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132012" version="502" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132013" version="502" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132014" version="502" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.10-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080132004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080132015" version="502" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134002" version="502" comment="tcltk is earlier than 0:8.3.5-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134003" version="502" comment="tcltk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134004" version="502" comment="tclx is earlier than 0:8.3-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134005" version="502" comment="tclx is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134006" version="502" comment="tcl is earlier than 0:8.3.5-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134007" version="502" comment="tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134008" version="502" comment="tk is earlier than 0:8.3.5-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134009" version="502" comment="tk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134010" version="502" comment="expect-devel is earlier than 0:5.38.0-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134011" version="502" comment="expect-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134012" version="502" comment="itcl is earlier than 0:3.2-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134013" version="502" comment="itcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134014" version="502" comment="expect is earlier than 0:5.38.0-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134015" version="502" comment="expect is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134016" version="502" comment="tcl-html is earlier than 0:8.3.5-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134017" version="502" comment="tcl-html is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134018" version="502" comment="tix is earlier than 0:8.1.4-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134019" version="502" comment="tix is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134020" version="502" comment="tcl-devel is earlier than 0:8.3.5-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134021" version="502" comment="tcl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134022" version="502" comment="tcllib is earlier than 0:1.3-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134023" version="502" comment="tcllib is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134024" version="502" comment="expectk is earlier than 0:5.38.0-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134025" version="502" comment="expectk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134026" version="502" comment="tk-devel is earlier than 0:8.3.5-92.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080134027" version="502" comment="tk-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080135002" version="503" comment="tk is earlier than 0:8.4.7-3.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080135003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080135004" version="503" comment="tk-devel is earlier than 0:8.4.7-3.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080135003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080136002" version="502" comment="tk is earlier than 0:8.4.13-5.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080136003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080136003" version="502" comment="tk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080136004" version="502" comment="tk-devel is earlier than 0:8.4.13-5.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080136003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080136005" version="502" comment="tk-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080134014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080144002" version="502" comment="acroread is earlier than 0:8.1.2-1.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080144002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080144004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080144003" version="502" comment="acroread is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080144002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080144004" version="502" comment="acroread-plugin is earlier than 0:8.1.2-1.el5.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080144003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080144004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080144005" version="502" comment="acroread-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080144003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145002" version="502" comment="ImageMagick is earlier than 0:6.2.8.0-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145003" version="502" comment="ImageMagick is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145004" version="502" comment="ImageMagick-devel is earlier than 0:6.2.8.0-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145005" version="502" comment="ImageMagick-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145006" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.2.8.0-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145007" version="502" comment="ImageMagick-c++-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145008" version="502" comment="ImageMagick-c++ is earlier than 0:6.2.8.0-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145009" version="502" comment="ImageMagick-c++ is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145010" version="502" comment="ImageMagick-perl is earlier than 0:6.2.8.0-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145011" version="502" comment="ImageMagick-perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145013" version="502" comment="ImageMagick is earlier than 0:5.5.6-28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145014" version="502" comment="ImageMagick is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145015" version="502" comment="ImageMagick-c++ is earlier than 0:5.5.6-28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145016" version="502" comment="ImageMagick-c++ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145017" version="502" comment="ImageMagick-perl is earlier than 0:5.5.6-28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145018" version="502" comment="ImageMagick-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145019" version="502" comment="ImageMagick-c++-devel is earlier than 0:5.5.6-28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145020" version="502" comment="ImageMagick-c++-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145021" version="502" comment="ImageMagick-devel is earlier than 0:5.5.6-28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145022" version="502" comment="ImageMagick-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145024" version="502" comment="ImageMagick is earlier than 0:6.0.7.1-17.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145025" version="502" comment="ImageMagick-c++ is earlier than 0:6.0.7.1-17.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145026" version="502" comment="ImageMagick-devel is earlier than 0:6.0.7.1-17.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145027" version="502" comment="ImageMagick-c++-devel is earlier than 0:6.0.7.1-17.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080145028" version="502" comment="ImageMagick-perl is earlier than 0:6.0.7.1-17.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080145006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080145008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146002" version="502" comment="gd is earlier than 0:2.0.33-9.4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080146004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146003" version="502" comment="gd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146004" version="502" comment="gd-devel is earlier than 0:2.0.33-9.4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080146004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146005" version="502" comment="gd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146006" version="502" comment="gd-progs is earlier than 0:2.0.33-9.4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080146004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146007" version="502" comment="gd-progs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146009" version="502" comment="gd is earlier than 0:2.0.28-5.4E.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080146006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146010" version="502" comment="gd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146011" version="502" comment="gd-progs is earlier than 0:2.0.28-5.4E.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080146006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146012" version="502" comment="gd-progs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146013" version="502" comment="gd-devel is earlier than 0:2.0.28-5.4E.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080146006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080146014" version="502" comment="gd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080146003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080153002" version="502" comment="cups is earlier than 1:1.1.17-13.3.51" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080153003" version="502" comment="cups is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080153004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.51" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080153005" version="502" comment="cups-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080153006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.51" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080153003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080153007" version="502" comment="cups-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154002" version="502" comment="kernel is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154004" version="502" comment="kernel-headers is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154006" version="502" comment="kernel-devel is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154008" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154010" version="502" comment="kernel-xen is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154012" version="502" comment="kernel-debug is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154014" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154016" version="502" comment="kernel-kdump is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154018" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080154024" version="502" comment="kernel-doc is earlier than 0:2.6.18-53.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155002" version="502" comment="ghostscript is earlier than 0:8.15.2-9.1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155003" version="502" comment="ghostscript is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155004" version="502" comment="ghostscript-devel is earlier than 0:8.15.2-9.1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155005" version="502" comment="ghostscript-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155006" version="502" comment="ghostscript-gtk is earlier than 0:8.15.2-9.1.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155007" version="502" comment="ghostscript-gtk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155009" version="502" comment="ghostscript is earlier than 0:7.05-32.1.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155010" version="502" comment="ghostscript is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155011" version="502" comment="ghostscript-devel is earlier than 0:7.05-32.1.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155012" version="502" comment="ghostscript-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155013" version="502" comment="hpijs is earlier than 0:1.3-32.1.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155014" version="502" comment="hpijs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155016" version="502" comment="ghostscript is earlier than 0:7.07-33.2.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155017" version="502" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155018" version="502" comment="ghostscript-gtk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080155019" version="502" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080155003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080155009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156002" version="503" comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080156004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156003" version="503" comment="java-1.5.0-bea is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156004" version="503" comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080156004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156005" version="503" comment="java-1.5.0-bea-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156006" version="503" comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080156004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156007" version="503" comment="java-1.5.0-bea-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156008" version="503" comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080156004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156009" version="503" comment="java-1.5.0-bea-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156010" version="503" comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080156004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156011" version="503" comment="java-1.5.0-bea-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156012" version="503" comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080156004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080156013" version="503" comment="java-1.5.0-bea-missioncontrol is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157002" version="502" comment="cups is earlier than 1:1.2.4-11.14.el5_1.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080157003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157003" version="502" comment="cups is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157004" version="502" comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080157003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157005" version="502" comment="cups-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157006" version="502" comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080157004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080157003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157007" version="502" comment="cups-lpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080157004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157008" version="502" comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080157003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080157009" version="502" comment="cups-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080159002" version="502" comment="dbus is earlier than 0:1.0.0-6.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080159003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080159003" version="502" comment="dbus is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080159004" version="502" comment="dbus-x11 is earlier than 0:1.0.0-6.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080159003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080159005" version="502" comment="dbus-x11 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080159006" version="502" comment="dbus-devel is earlier than 0:1.0.0-6.3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080159004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080159003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080159007" version="502" comment="dbus-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080159004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080161002" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080161003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080161004" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080161003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080161006" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080161003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164002" version="502" comment="krb5 is earlier than 0:1.6.1-17.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164003" version="502" comment="krb5 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164004" version="502" comment="krb5-devel is earlier than 0:1.6.1-17.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164005" version="502" comment="krb5-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164006" version="502" comment="krb5-libs is earlier than 0:1.6.1-17.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164007" version="502" comment="krb5-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164008" version="502" comment="krb5-server is earlier than 0:1.6.1-17.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164009" version="502" comment="krb5-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164010" version="502" comment="krb5-workstation is earlier than 0:1.6.1-17.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080164011" version="502" comment="krb5-workstation is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167002" version="502" comment="kernel is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167004" version="502" comment="kernel-devel is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167006" version="502" comment="kernel-xenU is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167008" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167010" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167012" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167014" version="502" comment="kernel-smp is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167016" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167018" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167020" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080167022" version="502" comment="kernel-doc is earlier than 0:2.6.9-67.0.7.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080167003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175002" version="502" comment="openoffice.org is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175003" version="502" comment="openoffice.org is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175004" version="502" comment="openoffice.org-javafilter is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175005" version="502" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175006" version="502" comment="openoffice.org-xsltfilter is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175007" version="502" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175008" version="502" comment="openoffice.org-langpack-es is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175009" version="502" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175010" version="502" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175011" version="502" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175012" version="502" comment="openoffice.org-graphicfilter is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175013" version="502" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175014" version="502" comment="openoffice.org-langpack-he_IL is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175015" version="502" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175016" version="502" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175017" version="502" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175018" version="502" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175019" version="502" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175020" version="502" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175021" version="502" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175022" version="502" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175023" version="502" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175024" version="502" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175025" version="502" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175026" version="502" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175027" version="502" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175028" version="502" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175029" version="502" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175030" version="502" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175031" version="502" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175032" version="502" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175033" version="502" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175034" version="502" comment="openoffice.org-langpack-bn is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175035" version="502" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175036" version="502" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175037" version="502" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175038" version="502" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175039" version="502" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175040" version="502" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175041" version="502" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175042" version="502" comment="openoffice.org-testtools is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175043" version="502" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175044" version="502" comment="openoffice.org-math is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175045" version="502" comment="openoffice.org-math is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175046" version="502" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175047" version="502" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175048" version="502" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175049" version="502" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175050" version="502" comment="openoffice.org-base is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175051" version="502" comment="openoffice.org-base is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175052" version="502" comment="openoffice.org-langpack-de is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175053" version="502" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175054" version="502" comment="openoffice.org-langpack-or_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175055" version="502" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175056" version="502" comment="openoffice.org-langpack-ur is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175057" version="502" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175058" version="502" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175059" version="502" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175060" version="502" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175061" version="502" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175062" version="502" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175063" version="502" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175064" version="502" comment="openoffice.org-emailmerge is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175065" version="502" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175066" version="502" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175067" version="502" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175068" version="502" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175069" version="502" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175070" version="502" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175071" version="502" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175072" version="502" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175073" version="502" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175074" version="502" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175075" version="502" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175076" version="502" comment="openoffice.org-langpack-el_GR is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175077" version="502" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175078" version="502" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175079" version="502" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175080" version="502" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175081" version="502" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175082" version="502" comment="openoffice.org-langpack-th_TH is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175083" version="502" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175084" version="502" comment="openoffice.org-core is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175085" version="502" comment="openoffice.org-core is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175086" version="502" comment="openoffice.org-langpack-sv is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175087" version="502" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175088" version="502" comment="openoffice.org-langpack-te_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175089" version="502" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175090" version="502" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175091" version="502" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175092" version="502" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175093" version="502" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175094" version="502" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175095" version="502" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175096" version="502" comment="openoffice.org-langpack-it is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175097" version="502" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175098" version="502" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175099" version="502" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175100" version="502" comment="openoffice.org-langpack-nl is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175101" version="502" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175102" version="502" comment="openoffice.org-langpack-da_DK is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175103" version="502" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175104" version="502" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175105" version="502" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175106" version="502" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175107" version="502" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175108" version="502" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175109" version="502" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175110" version="502" comment="openoffice.org-langpack-ru is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175111" version="502" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175112" version="502" comment="openoffice.org-writer is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175113" version="502" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175114" version="502" comment="openoffice.org-langpack-as_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175115" version="502" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175116" version="502" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175117" version="502" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175118" version="502" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175119" version="502" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175120" version="502" comment="openoffice.org-langpack-et_EE is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175121" version="502" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175122" version="502" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175123" version="502" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175124" version="502" comment="openoffice.org-calc is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175125" version="502" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175126" version="502" comment="openoffice.org-pyuno is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175127" version="502" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175128" version="502" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175129" version="502" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175130" version="502" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175131" version="502" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175132" version="502" comment="openoffice.org-langpack-ar is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175133" version="502" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175134" version="502" comment="openoffice.org-draw is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175135" version="502" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175136" version="502" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175137" version="502" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175138" version="502" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175139" version="502" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175140" version="502" comment="openoffice.org-impress is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175141" version="502" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175142" version="502" comment="openoffice.org-langpack-fr is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175143" version="502" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175144" version="502" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175145" version="502" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175146" version="502" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175147" version="502" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175148" version="502" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.0.4-5.4.26" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175149" version="502" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175151" version="502" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175076" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175152" version="502" comment="openoffice.org2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175076" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175153" version="502" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175077" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175154" version="502" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175077" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175155" version="502" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175078" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175156" version="502" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175078" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175157" version="502" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175079" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175158" version="502" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175079" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175159" version="502" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175080" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175160" version="502" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175080" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175161" version="502" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175081" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175162" version="502" comment="openoffice.org2-javafilter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175081" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175163" version="502" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175082" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175164" version="502" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175082" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175165" version="502" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175083" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175166" version="502" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175083" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175167" version="502" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175084" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175168" version="502" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175084" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175169" version="502" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175085" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175170" version="502" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175085" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175171" version="502" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175086" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175172" version="502" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175086" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175173" version="502" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175087" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175174" version="502" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175087" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175175" version="502" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175088" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175176" version="502" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175088" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175177" version="502" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175089" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175178" version="502" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175089" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175179" version="502" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175090" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175180" version="502" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175090" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175181" version="502" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175091" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175182" version="502" comment="openoffice.org2-langpack-de is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175091" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175183" version="502" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175092" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175184" version="502" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175092" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175185" version="502" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175093" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175186" version="502" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175093" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175187" version="502" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175094" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175188" version="502" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175094" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175189" version="502" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175095" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175190" version="502" comment="openoffice.org2-testtools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175095" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175191" version="502" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175096" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175192" version="502" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175096" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175193" version="502" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175097" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175194" version="502" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175097" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175195" version="502" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175098" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175196" version="502" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175098" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175197" version="502" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175099" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175198" version="502" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175099" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175199" version="502" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175100" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175200" version="502" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175100" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175201" version="502" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175101" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175202" version="502" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175101" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175203" version="502" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175102" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175204" version="502" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175102" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175205" version="502" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175103" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175206" version="502" comment="openoffice.org2-langpack-it is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175103" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175207" version="502" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175104" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175208" version="502" comment="openoffice.org2-calc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175104" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175209" version="502" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175105" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175210" version="502" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175105" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175211" version="502" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175106" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175212" version="502" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175106" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175213" version="502" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175107" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175214" version="502" comment="openoffice.org2-core is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175107" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175215" version="502" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175108" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175216" version="502" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175108" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175217" version="502" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175109" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175218" version="502" comment="openoffice.org2-base is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175109" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175219" version="502" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175110" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175220" version="502" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175110" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175221" version="502" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175111" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175222" version="502" comment="openoffice.org2-impress is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175111" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175223" version="502" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175112" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175224" version="502" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175112" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175225" version="502" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175113" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175226" version="502" comment="openoffice.org2-emailmerge is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175113" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175227" version="502" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175114" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175228" version="502" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175114" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175229" version="502" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175115" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175230" version="502" comment="openoffice.org2-math is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175115" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175231" version="502" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175116" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175232" version="502" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175116" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175233" version="502" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175117" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175234" version="502" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175117" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175235" version="502" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175118" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175236" version="502" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175118" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175237" version="502" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175119" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175238" version="502" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175119" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175239" version="502" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175120" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175240" version="502" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175120" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175241" version="502" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175121" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175242" version="502" comment="openoffice.org2-writer is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175121" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175243" version="502" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175122" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175244" version="502" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175122" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175245" version="502" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175123" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175246" version="502" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175123" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175247" version="502" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175124" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175248" version="502" comment="openoffice.org2-draw is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175124" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175249" version="502" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175125" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175250" version="502" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175125" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175251" version="502" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175126" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175252" version="502" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175126" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175253" version="502" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175127" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175254" version="502" comment="openoffice.org2-langpack-es is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175127" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175255" version="502" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175128" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175256" version="502" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175128" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175257" version="502" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175129" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175258" version="502" comment="openoffice.org2-pyuno is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175129" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175259" version="502" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175130" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175260" version="502" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175130" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175261" version="502" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175131" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175262" version="502" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175131" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175263" version="502" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175132" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175264" version="502" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175132" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175265" version="502" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175133" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175266" version="502" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175133" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175267" version="502" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.4.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175134" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080175006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080175268" version="502" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175134" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176002" version="502" comment="openoffice.org is earlier than 0:1.1.2-41.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176003" version="502" comment="openoffice.org is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176004" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-41.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176005" version="502" comment="openoffice.org-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176006" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-41.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176007" version="502" comment="openoffice.org-i18n is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176009" version="502" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176010" version="502" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176011" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176012" version="502" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.3.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080176005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080176013" version="502" comment="openoffice.org-kde is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177002" version="502" comment="evolution is earlier than 0:2.8.0-40.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080177004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177003" version="502" comment="evolution is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177004" version="502" comment="evolution-devel is earlier than 0:2.8.0-40.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080177004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177005" version="502" comment="evolution-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177007" version="502" comment="evolution is earlier than 0:2.0.2-35.0.4.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080177006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177008" version="502" comment="evolution is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177009" version="502" comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080177006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177010" version="502" comment="evolution-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177011" version="502" comment="evolution28 is earlier than 0:2.8.0-53.el4_6.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080177007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177012" version="502" comment="evolution28 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177013" version="502" comment="evolution28-devel is earlier than 0:2.8.0-53.el4_6.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080177007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080177014" version="502" comment="evolution28-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180002" version="502" comment="krb5 is earlier than 0:1.3.4-54.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080180003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180003" version="502" comment="krb5 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180004" version="502" comment="krb5-libs is earlier than 0:1.3.4-54.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080180003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180005" version="502" comment="krb5-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180006" version="502" comment="krb5-devel is earlier than 0:1.3.4-54.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080180003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180007" version="502" comment="krb5-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180008" version="502" comment="krb5-server is earlier than 0:1.3.4-54.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080180003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180009" version="502" comment="krb5-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180010" version="502" comment="krb5-workstation is earlier than 0:1.3.4-54.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080180003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080180011" version="502" comment="krb5-workstation is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080181002" version="502" comment="krb5 is earlier than 0:1.2.7-68" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080181003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080181004" version="502" comment="krb5-workstation is earlier than 0:1.2.7-68" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080181003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080181006" version="502" comment="krb5-server is earlier than 0:1.2.7-68" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080181003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080181008" version="502" comment="krb5-libs is earlier than 0:1.2.7-68" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080181003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080181010" version="502" comment="krb5-devel is earlier than 0:1.2.7-68" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080181003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080186002" version="502" comment="java-1.5.0-sun is earlier than 0:1.5.0.15-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080186004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080186004" version="502" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.15-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080186004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080186006" version="502" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.15-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080186004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080186008" version="502" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.15-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080186004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080186010" version="502" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.15-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080186004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080186012" version="502" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.15-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080123007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080186004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080192002" version="502" comment="cups is earlier than 1:1.2.4-11.14.el5_1.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080192003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080192004" version="502" comment="cups-libs is earlier than 1:1.2.4-11.14.el5_1.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080192003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080192006" version="502" comment="cups-devel is earlier than 1:1.2.4-11.14.el5_1.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080192003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080192008" version="502" comment="cups-lpd is earlier than 1:1.2.4-11.14.el5_1.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080157004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080192003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080194002" version="502" comment="xen is earlier than 0:3.0.3-41.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080194002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080194003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080194003" version="502" comment="xen is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080194002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080194004" version="502" comment="xen-devel is earlier than 0:3.0.3-41.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080194003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080194003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080194005" version="502" comment="xen-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080194003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080194006" version="502" comment="xen-libs is earlier than 0:3.0.3-41.el5_1.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080194004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080194003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080194007" version="502" comment="xen-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080194004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080196002" version="502" comment="unzip is earlier than 0:5.50-36.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080196002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080196003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080196003" version="502" comment="unzip is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080196002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080197002" version="502" comment="gnome-screensaver is earlier than 0:2.16.1-5.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080197002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080197003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080197003" version="502" comment="gnome-screensaver is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080197002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080206002" version="502" comment="cups is earlier than 1:1.1.17-13.3.52" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080206003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080206004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.52" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080206003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080206006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.52" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080206003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080206009" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080206005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080206010" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080206005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080206011" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080206005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080207002" version="502" comment="firefox is earlier than 0:1.5.0.12-14.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080207004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080207004" version="502" comment="firefox-devel is earlier than 0:1.5.0.12-14.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080207004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080207007" version="502" comment="firefox is earlier than 0:1.5.0.12-0.14.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080207006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208004" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208006" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208008" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208010" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208012" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208014" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208016" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208018" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208020" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.16.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208023" version="502" comment="seamonkey is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208024" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208025" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208026" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208027" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208028" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208029" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208030" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208031" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080208032" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080208005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080209002" version="502" comment="thunderbird is earlier than 0:1.5.0.12-11.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080209004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080209005" version="502" comment="thunderbird is earlier than 0:1.5.0.12-10.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080209006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210002" version="502" comment="java-1.5.0-ibm is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210003" version="502" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210004" version="502" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210005" version="502" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210006" version="502" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210007" version="502" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210008" version="502" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210009" version="502" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210010" version="502" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210011" version="502" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210012" version="502" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210013" version="502" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210014" version="502" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210015" version="502" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210016" version="502" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.7-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080210004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080210017" version="502" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080210009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211002" version="502" comment="kernel is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211004" version="502" comment="kernel-smp is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211006" version="502" comment="kernel-unsupported is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211007" version="502" comment="kernel-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211008" version="502" comment="kernel-smp-unsupported is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211009" version="502" comment="kernel-smp-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211010" version="502" comment="kernel-doc is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211012" version="502" comment="kernel-source is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211013" version="502" comment="kernel-source is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211014" version="502" comment="kernel-BOOT is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211015" version="502" comment="kernel-BOOT is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211016" version="502" comment="kernel-hugemem is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211018" version="502" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-57.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080211003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080211019" version="502" comment="kernel-hugemem-unsupported is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080211010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080214002" version="502" comment="squid is earlier than 7:2.6.STABLE6-5.el5_1.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080214002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080214004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080214003" version="502" comment="squid is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080214002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080214005" version="502" comment="squid is earlier than 7:2.5.STABLE3-9.3E" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080214002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080214006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080214006" version="502" comment="squid is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080214002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080214008" version="502" comment="squid is earlier than 7:2.5.STABLE14-1.4E.el4_6.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080214002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080214008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080218002" version="502" comment="gnome-screensaver is earlier than 0:2.16.1-8.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080197002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080218003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080221002" version="502" comment="flash-plugin is earlier than 0:9.0.124.0-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080221002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080221004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080221003" version="502" comment="flash-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080221002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080222002" version="503" comment="firefox is earlier than 0:1.5.0.12-15.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080222004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080222004" version="503" comment="firefox-devel is earlier than 0:1.5.0.12-15.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080222004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080222007" version="503" comment="firefox is earlier than 0:1.5.0.12-0.15.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080222006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223002" version="503" comment="seamonkey is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223004" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223006" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223008" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223010" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223012" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223014" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223016" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223018" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223020" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.17.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223023" version="503" comment="seamonkey is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223024" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223025" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223026" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223027" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223028" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223029" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223030" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223031" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080223032" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080223005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080224002" version="502" comment="thunderbird is earlier than 0:1.5.0.12-12.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080224004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080224005" version="502" comment="thunderbird is earlier than 0:1.5.0.12-11.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080105002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080224006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233002" version="502" comment="kernel is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233004" version="502" comment="kernel-headers is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233006" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233008" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233010" version="502" comment="kernel-debug is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233012" version="502" comment="kernel-xen is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233014" version="502" comment="kernel-devel is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233016" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233018" version="502" comment="kernel-kdump is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080233024" version="502" comment="kernel-doc is earlier than 0:2.6.18-53.1.19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080233003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235002" version="502" comment="speex is earlier than 0:1.0.5-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080235004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235003" version="502" comment="speex is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235004" version="502" comment="speex-devel is earlier than 0:1.0.5-4.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080235004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235005" version="502" comment="speex-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235007" version="502" comment="speex is earlier than 0:1.0.4-4.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080235006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235008" version="502" comment="speex is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235009" version="502" comment="speex-devel is earlier than 0:1.0.4-4.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080235006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080235010" version="502" comment="speex-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080235003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237002" version="502" comment="kernel is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237004" version="502" comment="kernel-devel is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237006" version="502" comment="kernel-smp is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237008" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237010" version="502" comment="kernel-xenU is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237012" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237014" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237016" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080237022" version="502" comment="kernel-doc is earlier than 0:2.6.9-67.0.15.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080237003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080238002" version="502" comment="kdegraphics is earlier than 7:3.3.1-9.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080238003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080238003" version="502" comment="kdegraphics is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080238002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080238004" version="502" comment="kdegraphics-devel is earlier than 7:3.3.1-9.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080238003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080238005" version="502" comment="kdegraphics-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080238003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080239002" version="502" comment="poppler is earlier than 0:0.5.4-4.4.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080239002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080239003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080239003" version="502" comment="poppler is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080239002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080239004" version="502" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080239003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080239003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080239005" version="502" comment="poppler-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080239003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080239006" version="502" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080239004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080239003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080239007" version="502" comment="poppler-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080239004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080240002" version="502" comment="xpdf is earlier than 1:3.00-16.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080240002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080240003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080240003" version="502" comment="xpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080240002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080243002" version="502" comment="java-1.4.2-bea is earlier than 0:1.4.2.16-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080243004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080243004" version="502" comment="java-1.4.2-bea-devel is earlier than 0:1.4.2.16-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080243004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080243006" version="502" comment="java-1.4.2-bea-src is earlier than 0:1.4.2.16-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080243004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080243008" version="502" comment="java-1.4.2-bea-demo is earlier than 0:1.4.2.16-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080243004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080243010" version="502" comment="java-1.4.2-bea-jdbc is earlier than 0:1.4.2.16-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080243004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080243012" version="502" comment="java-1.4.2-bea-missioncontrol is earlier than 0:1.4.2.16-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080100007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080243004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080244002" version="502" comment="java-1.5.0-bea is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080244004" version="502" comment="java-1.5.0-bea-devel is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080244006" version="502" comment="java-1.5.0-bea-src is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080244008" version="502" comment="java-1.5.0-bea-demo is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080244010" version="502" comment="java-1.5.0-bea-jdbc is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080244012" version="502" comment="java-1.5.0-bea-missioncontrol is earlier than 0:1.5.0.14-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080156007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080123004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245002" version="502" comment="java-1.6.0-bea is earlier than 1:1.6.0.03-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245003" version="502" comment="java-1.6.0-bea is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245004" version="502" comment="java-1.6.0-bea-jdbc is earlier than 1:1.6.0.03-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245005" version="502" comment="java-1.6.0-bea-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245006" version="502" comment="java-1.6.0-bea-devel is earlier than 1:1.6.0.03-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245007" version="502" comment="java-1.6.0-bea-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245008" version="502" comment="java-1.6.0-bea-missioncontrol is earlier than 1:1.6.0.03-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245009" version="502" comment="java-1.6.0-bea-missioncontrol is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245010" version="502" comment="java-1.6.0-bea-src is earlier than 1:1.6.0.03-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245011" version="502" comment="java-1.6.0-bea-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245012" version="502" comment="java-1.6.0-bea-demo is earlier than 1:1.6.0.03-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080245003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080245013" version="502" comment="java-1.6.0-bea-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080245007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080262002" version="502" comment="gpdf is earlier than 0:2.8.2-7.7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080262002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080262003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080262003" version="502" comment="gpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080262002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267002" version="502" comment="java-1.6.0-ibm is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267003" version="502" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267004" version="502" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267005" version="502" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267006" version="502" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267007" version="502" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267008" version="502" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267009" version="502" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267010" version="502" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267011" version="502" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267012" version="502" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267013" version="502" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267014" version="502" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267015" version="502" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267016" version="502" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.1-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080267017" version="502" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080267009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270002" version="502" comment="libvorbis is earlier than 1:1.1.2-3.el5_1.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080270004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270003" version="502" comment="libvorbis is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270004" version="502" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_1.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080270004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270005" version="502" comment="libvorbis-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270007" version="502" comment="libvorbis is earlier than 1:1.0-10.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080270006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270008" version="502" comment="libvorbis is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270009" version="502" comment="libvorbis-devel is earlier than 1:1.0-10.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080270006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270010" version="502" comment="libvorbis-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270012" version="502" comment="libvorbis is earlier than 1:1.1.0-3.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080270008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080270013" version="502" comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080270003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080270008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275002" version="502" comment="kernel is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275004" version="502" comment="kernel-headers is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275006" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275008" version="502" comment="kernel-debug is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275010" version="502" comment="kernel-xen is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275012" version="502" comment="kernel-devel is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275014" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275016" version="502" comment="kernel-kdump is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275018" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275020" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275022" version="502" comment="kernel-PAE is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080275024" version="502" comment="kernel-doc is earlier than 0:2.6.18-53.1.21.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287002" version="502" comment="libxslt is earlier than 0:1.1.17-2.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287003" version="502" comment="libxslt is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287004" version="502" comment="libxslt-python is earlier than 0:1.1.17-2.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287005" version="502" comment="libxslt-python is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287006" version="502" comment="libxslt-devel is earlier than 0:1.1.17-2.el5_1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287007" version="502" comment="libxslt-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287009" version="502" comment="libxslt is earlier than 0:1.0.33-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287010" version="502" comment="libxslt is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287011" version="502" comment="libxslt-python is earlier than 0:1.0.33-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287012" version="502" comment="libxslt-python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287013" version="502" comment="libxslt-devel is earlier than 0:1.0.33-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287014" version="502" comment="libxslt-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287016" version="502" comment="libxslt is earlier than 0:1.1.11-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287017" version="502" comment="libxslt-devel is earlier than 0:1.1.11-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080287018" version="502" comment="libxslt-python is earlier than 0:1.1.11-1.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080287003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080287008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288002" version="502" comment="samba is earlier than 0:3.0.9-1.3E.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288003" version="502" comment="samba is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288004" version="502" comment="samba-swat is earlier than 0:3.0.9-1.3E.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288005" version="502" comment="samba-swat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288006" version="502" comment="samba-common is earlier than 0:3.0.9-1.3E.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288007" version="502" comment="samba-common is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288008" version="502" comment="samba-client is earlier than 0:3.0.9-1.3E.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288009" version="502" comment="samba-client is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288011" version="502" comment="samba is earlier than 0:3.0.25b-1.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288012" version="502" comment="samba-common is earlier than 0:3.0.25b-1.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288013" version="502" comment="samba-swat is earlier than 0:3.0.25b-1.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080288014" version="502" comment="samba-client is earlier than 0:3.0.25b-1.el4_6.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080288005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290002" version="502" comment="samba is earlier than 0:3.0.28-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080290003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290003" version="502" comment="samba is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290004" version="502" comment="samba-swat is earlier than 0:3.0.28-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080290003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290005" version="502" comment="samba-swat is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290006" version="502" comment="samba-common is earlier than 0:3.0.28-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080290003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290007" version="502" comment="samba-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290008" version="502" comment="samba-client is earlier than 0:3.0.28-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080290003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080290009" version="502" comment="samba-client is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080288005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080295002" version="502" comment="vsftpd is earlier than 0:2.0.5-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080295003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080295003" version="502" comment="vsftpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080297002" version="503" comment="dovecot is earlier than 0:1.0.7-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080297002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080297003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080297003" version="503" comment="dovecot is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080297002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300002" version="503" comment="bind is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300003" version="503" comment="bind is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300004" version="503" comment="bind-devel is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300005" version="503" comment="bind-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300006" version="503" comment="bind-libbind-devel is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300007" version="503" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300008" version="503" comment="bind-sdb is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300009" version="503" comment="bind-sdb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300010" version="503" comment="bind-libs is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300011" version="503" comment="bind-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300012" version="503" comment="caching-nameserver is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300013" version="503" comment="caching-nameserver is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300014" version="503" comment="bind-chroot is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300015" version="503" comment="bind-chroot is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300016" version="503" comment="bind-utils is earlier than 30:9.3.4-6.P1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080300003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080300017" version="503" comment="bind-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364002" version="502" comment="mysql is earlier than 0:5.0.45-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080364003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364003" version="502" comment="mysql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364004" version="502" comment="mysql-server is earlier than 0:5.0.45-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080364003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364005" version="502" comment="mysql-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364006" version="502" comment="mysql-devel is earlier than 0:5.0.45-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080364003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364007" version="502" comment="mysql-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364008" version="502" comment="mysql-bench is earlier than 0:5.0.45-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080364003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364009" version="502" comment="mysql-bench is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364010" version="502" comment="mysql-test is earlier than 0:5.0.45-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080364003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080364011" version="502" comment="mysql-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080364006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080389002" version="503" comment="nss_ldap is earlier than 0:253-12.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080389003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080389003" version="503" comment="nss_ldap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080389002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080485002" version="503" comment="compiz is earlier than 0:0.0.13-0.37.20060817git.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080485002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080485003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080485003" version="503" comment="compiz is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080485002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080485004" version="503" comment="compiz-devel is earlier than 0:0.0.13-0.37.20060817git.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080485003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080485003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080485005" version="503" comment="compiz-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080485003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080486002" version="502" comment="nfs-utils is earlier than 1:1.0.9-35z.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080486002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080486003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080486003" version="502" comment="nfs-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080486002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080489002" version="502" comment="gnutls is earlier than 0:1.4.1-3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080489003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080489003" version="502" comment="gnutls is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080489004" version="502" comment="gnutls-devel is earlier than 0:1.4.1-3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080489003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080489005" version="502" comment="gnutls-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080489006" version="502" comment="gnutls-utils is earlier than 0:1.4.1-3.el5_1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080489003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080489007" version="502" comment="gnutls-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080492002" version="502" comment="gnutls is earlier than 0:1.0.20-4.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080492003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080492003" version="502" comment="gnutls is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080492004" version="502" comment="gnutls-devel is earlier than 0:1.0.20-4.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080492003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080492005" version="502" comment="gnutls-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080489003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497002" version="502" comment="sblim is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497003" version="502" comment="sblim is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497004" version="502" comment="sblim-cmpi-base-test is earlier than 0:1.5.5-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497005" version="502" comment="sblim-cmpi-base-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497006" version="502" comment="sblim-cmpi-base is earlier than 0:1.5.5-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497007" version="502" comment="sblim-cmpi-base is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497008" version="502" comment="sblim-cmpi-dns-devel is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497009" version="502" comment="sblim-cmpi-dns-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497010" version="502" comment="sblim-cmpi-params-test is earlier than 0:1.2.6-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497011" version="502" comment="sblim-cmpi-params-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497012" version="502" comment="sblim-wbemcli is earlier than 0:1.5.1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497013" version="502" comment="sblim-wbemcli is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497014" version="502" comment="sblim-cmpi-params is earlier than 0:1.2.6-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497015" version="502" comment="sblim-cmpi-params is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497016" version="502" comment="sblim-cmpi-fsvol is earlier than 0:1.4.4-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497017" version="502" comment="sblim-cmpi-fsvol is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497018" version="502" comment="sblim-gather-devel is earlier than 0:2.1.2-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497019" version="502" comment="sblim-gather-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497020" version="502" comment="sblim-cmpi-sysfs is earlier than 0:1.1.9-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497021" version="502" comment="sblim-cmpi-sysfs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497022" version="502" comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.14-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497011" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497023" version="502" comment="sblim-cmpi-nfsv3-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497024" version="502" comment="sblim-cmpi-samba-test is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497025" version="502" comment="sblim-cmpi-samba-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497026" version="502" comment="sblim-cmpi-dns is earlier than 0:0.5.2-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497012" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497027" version="502" comment="sblim-cmpi-dns is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497028" version="502" comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.9-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497029" version="502" comment="sblim-cmpi-sysfs-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497030" version="502" comment="sblim-cmpi-network-test is earlier than 0:1.3.8-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497013" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497031" version="502" comment="sblim-cmpi-network-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497032" version="502" comment="sblim-gather is earlier than 0:2.1.2-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497033" version="502" comment="sblim-gather is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497034" version="502" comment="sblim-tools-libra is earlier than 0:0.2.3-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497014" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497035" version="502" comment="sblim-tools-libra is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497036" version="502" comment="sblim-cim-client-manual is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497037" version="502" comment="sblim-cim-client-manual is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497038" version="502" comment="sblim-cmpi-samba is earlier than 0:0.5.2-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497012" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497039" version="502" comment="sblim-cmpi-samba is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497040" version="502" comment="sblim-cmpi-samba-devel is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497041" version="502" comment="sblim-cmpi-samba-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497042" version="502" comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.4-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497043" version="502" comment="sblim-cmpi-fsvol-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497044" version="502" comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.12-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497015" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497045" version="502" comment="sblim-cmpi-nfsv4 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497046" version="502" comment="sblim-cmpi-network is earlier than 0:1.3.8-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497013" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497047" version="502" comment="sblim-cmpi-network is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497048" version="502" comment="sblim-cim-client is earlier than 0:1.3.3-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497016" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497049" version="502" comment="sblim-cim-client is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497050" version="502" comment="sblim-gather-provider is earlier than 0:2.1.2-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497051" version="502" comment="sblim-gather-provider is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497052" version="502" comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.12-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497015" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497053" version="502" comment="sblim-cmpi-nfsv4-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497054" version="502" comment="sblim-cmpi-syslog-test is earlier than 0:0.7.11-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497017" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497055" version="502" comment="sblim-cmpi-syslog-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497056" version="502" comment="sblim-cmpi-network-devel is earlier than 0:1.3.8-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497013" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497057" version="502" comment="sblim-cmpi-network-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497058" version="502" comment="sblim-cmpi-base-devel is earlier than 0:1.5.5-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497059" version="502" comment="sblim-cmpi-base-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497060" version="502" comment="sblim-gather-test is earlier than 0:2.1.2-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497061" version="502" comment="sblim-gather-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497062" version="502" comment="sblim-cim-client-javadoc is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497063" version="502" comment="sblim-cim-client-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497064" version="502" comment="sblim-cmpi-devel is earlier than 0:1.0.4-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497018" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497065" version="502" comment="sblim-cmpi-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497066" version="502" comment="sblim-tools-libra-devel is earlier than 0:0.2.3-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497014" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497067" version="502" comment="sblim-tools-libra-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497068" version="502" comment="sblim-testsuite is earlier than 0:1.2.4-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497019" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497069" version="502" comment="sblim-testsuite is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497070" version="502" comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.4-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497071" version="502" comment="sblim-cmpi-fsvol-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497072" version="502" comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.14-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497011" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497073" version="502" comment="sblim-cmpi-nfsv3 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497074" version="502" comment="sblim-cmpi-syslog is earlier than 0:0.7.11-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497017" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497075" version="502" comment="sblim-cmpi-syslog is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497076" version="502" comment="sblim-cmpi-dns-test is earlier than 0:1-31.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497077" version="502" comment="sblim-cmpi-dns-test is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497079" version="502" comment="sblim is earlier than 0:1-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497021" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497080" version="502" comment="sblim is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497081" version="502" comment="sblim-gather-devel is earlier than 0:2.1.1-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497022" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497082" version="502" comment="sblim-gather-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497083" version="502" comment="sblim-cmpi-params-test is earlier than 0:1.2.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497023" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497084" version="502" comment="sblim-cmpi-params-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497085" version="502" comment="sblim-testsuite is earlier than 0:1.2.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497023" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497086" version="502" comment="sblim-testsuite is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497087" version="502" comment="sblim-wbemcli is earlier than 0:1.5.1-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497024" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497088" version="502" comment="sblim-wbemcli is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497089" version="502" comment="sblim-cmpi-sysfs is earlier than 0:1.1.8-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497025" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497090" version="502" comment="sblim-cmpi-sysfs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497091" version="502" comment="sblim-cmpi-base is earlier than 0:1.5.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497026" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497092" version="502" comment="sblim-cmpi-base is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497093" version="502" comment="sblim-cmpi-syslog-test is earlier than 0:0.7.9-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497027" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497094" version="502" comment="sblim-cmpi-syslog-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497095" version="502" comment="sblim-cmpi-sysfs-test is earlier than 0:1.1.8-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497025" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497096" version="502" comment="sblim-cmpi-sysfs-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497097" version="502" comment="sblim-gather is earlier than 0:2.1.1-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497022" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497098" version="502" comment="sblim-gather is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497099" version="502" comment="sblim-cmpi-nfsv4 is earlier than 0:1.0.11-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497028" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497100" version="502" comment="sblim-cmpi-nfsv4 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497101" version="502" comment="sblim-cmpi-fsvol-devel is earlier than 0:1.4.3-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497029" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497102" version="502" comment="sblim-cmpi-fsvol-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497103" version="502" comment="sblim-cmpi-syslog is earlier than 0:0.7.9-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497027" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497104" version="502" comment="sblim-cmpi-syslog is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497105" version="502" comment="sblim-cmpi-network is earlier than 0:1.3.7-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497030" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497106" version="502" comment="sblim-cmpi-network is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497107" version="502" comment="sblim-cmpi-fsvol-test is earlier than 0:1.4.3-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497029" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497108" version="502" comment="sblim-cmpi-fsvol-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497109" version="502" comment="sblim-cmpi-params is earlier than 0:1.2.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497023" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497110" version="502" comment="sblim-cmpi-params is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497111" version="502" comment="sblim-cmpi-network-test is earlier than 0:1.3.7-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497030" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497112" version="502" comment="sblim-cmpi-network-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497113" version="502" comment="sblim-gather-test is earlier than 0:2.1.1-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497022" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497114" version="502" comment="sblim-gather-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497115" version="502" comment="sblim-cmpi-fsvol is earlier than 0:1.4.3-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497029" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497116" version="502" comment="sblim-cmpi-fsvol is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497117" version="502" comment="sblim-gather-provider is earlier than 0:2.1.1-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497022" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497118" version="502" comment="sblim-gather-provider is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497119" version="502" comment="sblim-cmpi-base-devel is earlier than 0:1.5.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497026" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497120" version="502" comment="sblim-cmpi-base-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497121" version="502" comment="sblim-cmpi-nfsv3 is earlier than 0:1.0.13-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497031" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497122" version="502" comment="sblim-cmpi-nfsv3 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497123" version="502" comment="sblim-cmpi-network-devel is earlier than 0:1.3.7-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497030" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497124" version="502" comment="sblim-cmpi-network-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497125" version="502" comment="sblim-cmpi-nfsv4-test is earlier than 0:1.0.11-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497028" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497126" version="502" comment="sblim-cmpi-nfsv4-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497127" version="502" comment="sblim-cmpi-nfsv3-test is earlier than 0:1.0.13-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497031" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497128" version="502" comment="sblim-cmpi-nfsv3-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497129" version="502" comment="sblim-cmpi-base-test is earlier than 0:1.5.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497026" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497130" version="502" comment="sblim-cmpi-base-test is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497131" version="502" comment="sblim-cmpi-devel is earlier than 0:1.0.4-13a.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080497032" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080497132" version="502" comment="sblim-cmpi-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080497033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498002" version="503" comment="cups is earlier than 1:1.2.4-11.18.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498004" version="503" comment="cups-libs is earlier than 1:1.2.4-11.18.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498006" version="503" comment="cups-lpd is earlier than 1:1.2.4-11.18.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080157004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498008" version="503" comment="cups-devel is earlier than 1:1.2.4-11.18.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498011" version="503" comment="cups is earlier than 1:1.1.17-13.3.53" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498013" version="503" comment="cups-libs is earlier than 1:1.1.17-13.3.53" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498015" version="503" comment="cups-devel is earlier than 1:1.1.17-13.3.53" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498018" version="503" comment="cups is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498019" version="503" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080498020" version="503" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.20.2.el4_6.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080153003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080498008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502002" version="502" comment="XFree86 is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502004" version="502" comment="XFree86-xfs is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502006" version="502" comment="XFree86-doc is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502008" version="502" comment="XFree86-devel is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502010" version="502" comment="XFree86-sdk is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502012" version="502" comment="XFree86-xauth is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502014" version="502" comment="XFree86-Mesa-libGLU is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502016" version="502" comment="XFree86-ISO8859-14-75dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502018" version="502" comment="XFree86-ISO8859-2-100dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502020" version="502" comment="XFree86-base-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502022" version="502" comment="XFree86-100dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502024" version="502" comment="XFree86-truetype-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502026" version="502" comment="XFree86-libs is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502028" version="502" comment="XFree86-Mesa-libGL is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502030" version="502" comment="XFree86-ISO8859-15-100dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502032" version="502" comment="XFree86-75dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502034" version="502" comment="XFree86-libs-data is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502036" version="502" comment="XFree86-syriac-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502038" version="502" comment="XFree86-twm is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502040" version="502" comment="XFree86-cyrillic-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502042" version="502" comment="XFree86-ISO8859-15-75dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502044" version="502" comment="XFree86-ISO8859-9-75dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502046" version="502" comment="XFree86-ISO8859-14-100dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502048" version="502" comment="XFree86-ISO8859-2-75dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502050" version="502" comment="XFree86-ISO8859-9-100dpi-fonts is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502052" version="502" comment="XFree86-font-utils is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502054" version="502" comment="XFree86-Xvfb is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502056" version="502" comment="XFree86-Xnest is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502058" version="502" comment="XFree86-xdm is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080502060" version="502" comment="XFree86-tools is earlier than 0:4.3.0-128.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080029009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080502003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503002" version="502" comment="xorg-x11 is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503004" version="502" comment="xorg-x11-Mesa-libGL is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503006" version="502" comment="xorg-x11-sdk is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503008" version="502" comment="xorg-x11-doc is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503010" version="502" comment="xorg-x11-Xnest is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503012" version="502" comment="xorg-x11-tools is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503014" version="502" comment="xorg-x11-font-utils is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503016" version="502" comment="xorg-x11-deprecated-libs is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503018" version="502" comment="xorg-x11-libs is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503020" version="502" comment="xorg-x11-xfs is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503022" version="502" comment="xorg-x11-deprecated-libs-devel is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503024" version="502" comment="xorg-x11-Mesa-libGLU is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503026" version="502" comment="xorg-x11-xauth is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503028" version="502" comment="xorg-x11-twm is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503030" version="502" comment="xorg-x11-xdm is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503032" version="502" comment="xorg-x11-Xvfb is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503034" version="502" comment="xorg-x11-Xdmx is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080503036" version="502" comment="xorg-x11-devel is earlier than 0:6.8.2-1.EL.33.0.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080030016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080503003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504002" version="502" comment="xorg-x11-server is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504004" version="502" comment="xorg-x11-server-randr-source is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080504003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504005" version="502" comment="xorg-x11-server-randr-source is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080504003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504006" version="502" comment="xorg-x11-server-Xorg is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504008" version="502" comment="xorg-x11-server-Xnest is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504010" version="502" comment="xorg-x11-server-sdk is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504012" version="502" comment="xorg-x11-server-Xvfb is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504014" version="502" comment="xorg-x11-server-Xdmx is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080504016" version="502" comment="xorg-x11-server-Xephyr is earlier than 0:1.1.1-48.41.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080031003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080504003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508002" version="502" comment="kernel is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508004" version="502" comment="kernel-devel is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508006" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508008" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508010" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508012" version="502" comment="kernel-smp is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508014" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508016" version="502" comment="kernel-xenU is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080508022" version="502" comment="kernel-doc is earlier than 0:2.6.9-67.0.20.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080508003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080514002" version="502" comment="evolution is earlier than 0:2.12.3-8.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080514004" version="502" comment="evolution-devel is earlier than 0:2.12.3-8.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080514006" version="502" comment="evolution-help is earlier than 0:2.12.3-8.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080514004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080514003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080514007" version="502" comment="evolution-help is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080514004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080515002" version="502" comment="evolution28 is earlier than 0:2.8.0-53.el4_6.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080515003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080515004" version="502" comment="evolution28-devel is earlier than 0:2.8.0-53.el4_6.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080515003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080516002" version="502" comment="evolution is earlier than 0:1.4.5-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080516003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080516004" version="502" comment="evolution-devel is earlier than 0:1.4.5-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080516003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080516007" version="502" comment="evolution is earlier than 0:2.0.2-35.0.4.el4_6.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080516005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080516008" version="502" comment="evolution-devel is earlier than 0:2.0.2-35.0.4.el4_6.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080516005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519002" version="502" comment="kernel is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519004" version="502" comment="kernel-headers is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519006" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519008" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519010" version="502" comment="kernel-debug is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519012" version="502" comment="kernel-xen is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519014" version="502" comment="kernel-devel is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519016" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519018" version="502" comment="kernel-kdump is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080089012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080519024" version="502" comment="kernel-doc is earlier than 0:2.6.18-92.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080055012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080519003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522002" version="502" comment="perl is earlier than 4:5.8.8-10.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522003" version="502" comment="perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522004" version="502" comment="perl-suidperl is earlier than 4:5.8.8-10.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522005" version="502" comment="perl-suidperl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522007" version="502" comment="perl is earlier than 2:5.8.0-98.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522008" version="502" comment="perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522009" version="502" comment="perl-suidperl is earlier than 2:5.8.0-98.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522010" version="502" comment="perl-suidperl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522011" version="502" comment="perl-CPAN is earlier than 2:1.61-98.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522012" version="502" comment="perl-CPAN is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522013" version="502" comment="perl-CGI is earlier than 2:2.89-98.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522014" version="502" comment="perl-CGI is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522015" version="502" comment="perl-DB_File is earlier than 2:1.806-98.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522016" version="502" comment="perl-DB_File is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522018" version="502" comment="perl is earlier than 3:5.8.5-36.el4_6.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522011" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080522019" version="502" comment="perl-suidperl is earlier than 3:5.8.5-36.el4_6.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080522003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080522011" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529002" version="502" comment="net-snmp is earlier than 1:5.3.1-24.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529003" version="502" comment="net-snmp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529004" version="502" comment="net-snmp-devel is earlier than 1:5.3.1-24.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529005" version="502" comment="net-snmp-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529006" version="502" comment="net-snmp-utils is earlier than 1:5.3.1-24.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529007" version="502" comment="net-snmp-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529008" version="502" comment="net-snmp-perl is earlier than 1:5.3.1-24.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529009" version="502" comment="net-snmp-perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529010" version="502" comment="net-snmp-libs is earlier than 1:5.3.1-24.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529011" version="502" comment="net-snmp-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529013" version="502" comment="net-snmp is earlier than 0:5.0.9-2.30E.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529014" version="502" comment="net-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529015" version="502" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529016" version="502" comment="net-snmp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529017" version="502" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529018" version="502" comment="net-snmp-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529019" version="502" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529020" version="502" comment="net-snmp-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529021" version="502" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.24" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529022" version="502" comment="net-snmp-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529024" version="502" comment="net-snmp is earlier than 0:5.1.2-11.el4_6.11.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529025" version="502" comment="net-snmp-libs is earlier than 0:5.1.2-11.el4_6.11.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529026" version="502" comment="net-snmp-perl is earlier than 0:5.1.2-11.el4_6.11.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529027" version="502" comment="net-snmp-devel is earlier than 0:5.1.2-11.el4_6.11.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080529028" version="502" comment="net-snmp-utils is earlier than 0:5.1.2-11.el4_6.11.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080529004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080529008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533002" version="503" comment="selinux-policy is earlier than 0:2.4.6-137.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533003" version="503" comment="selinux-policy is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533004" version="503" comment="selinux-policy-devel is earlier than 0:2.4.6-137.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533005" version="503" comment="selinux-policy-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533006" version="503" comment="selinux-policy-targeted is earlier than 0:2.4.6-137.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533007" version="503" comment="selinux-policy-targeted is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533008" version="503" comment="selinux-policy-mls is earlier than 0:2.4.6-137.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533009" version="503" comment="selinux-policy-mls is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533010" version="503" comment="selinux-policy-strict is earlier than 0:2.4.6-137.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533011" version="503" comment="selinux-policy-strict is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533012" version="503" comment="bind is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533014" version="503" comment="caching-nameserver is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533016" version="503" comment="bind-libs is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533018" version="503" comment="bind-chroot is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533020" version="503" comment="bind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533022" version="503" comment="bind-utils is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533024" version="503" comment="bind-sdb is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533026" version="503" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.2.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533029" version="503" comment="bind is earlier than 20:9.2.4-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533030" version="503" comment="bind is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533031" version="503" comment="bind-devel is earlier than 20:9.2.4-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533032" version="503" comment="bind-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533033" version="503" comment="bind-libs is earlier than 20:9.2.4-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533034" version="503" comment="bind-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533035" version="503" comment="bind-utils is earlier than 20:9.2.4-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533036" version="503" comment="bind-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533037" version="503" comment="bind-chroot is earlier than 20:9.2.4-22.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533038" version="503" comment="bind-chroot is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533040" version="503" comment="bind is earlier than 20:9.2.4-28.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533041" version="503" comment="bind-chroot is earlier than 20:9.2.4-28.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533042" version="503" comment="bind-devel is earlier than 20:9.2.4-28.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533043" version="503" comment="bind-utils is earlier than 20:9.2.4-28.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533044" version="503" comment="bind-libs is earlier than 20:9.2.4-28.0.1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080300006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533045" version="503" comment="selinux-policy-targeted is earlier than 0:1.17.30-2.150.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533046" version="503" comment="selinux-policy-targeted is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533047" version="503" comment="selinux-policy-targeted-sources is earlier than 0:1.17.30-2.150.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080533010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080533048" version="503" comment="selinux-policy-targeted-sources is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080533015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537002" version="502" comment="openoffice.org is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537004" version="502" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175058" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537006" version="502" comment="openoffice.org-math is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175023" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537008" version="502" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175036" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537010" version="502" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537012" version="502" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175044" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537014" version="502" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175034" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537016" version="502" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175039" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537018" version="502" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175067" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537020" version="502" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537022" version="502" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175062" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537024" version="502" comment="openoffice.org-headless is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080537013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537025" version="502" comment="openoffice.org-headless is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080537013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537026" version="502" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537028" version="502" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175072" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537030" version="502" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175022" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537032" version="502" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537034" version="502" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175037" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537036" version="502" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175038" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537038" version="502" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175030" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537040" version="502" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175064" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537042" version="502" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175059" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537044" version="502" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175065" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537046" version="502" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175055" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537048" version="502" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537050" version="502" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175025" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537052" version="502" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537054" version="502" comment="openoffice.org-writer is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175057" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537056" version="502" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175070" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537058" version="502" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537060" version="502" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537062" version="502" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175028" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537064" version="502" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175060" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537066" version="502" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175045" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537068" version="502" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175051" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537070" version="502" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537072" version="502" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175047" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537074" version="502" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175075" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537076" version="502" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537078" version="502" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537080" version="502" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175048" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537082" version="502" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175049" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537084" version="502" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175041" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537086" version="502" comment="openoffice.org-calc is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175063" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537088" version="502" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175040" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537090" version="502" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175046" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537092" version="502" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175073" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537094" version="502" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175074" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537096" version="502" comment="openoffice.org-draw is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175068" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537098" version="502" comment="openoffice.org-impress is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175071" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537100" version="502" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537102" version="502" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175029" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537104" version="502" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537106" version="502" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537108" version="502" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175050" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537110" version="502" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175052" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537112" version="502" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175021" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537114" version="502" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175066" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537116" version="502" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175033" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537118" version="502" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175053" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537120" version="502" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080537061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537121" version="502" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080537061" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537122" version="502" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175056" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537124" version="502" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537126" version="502" comment="openoffice.org-core is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175043" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537128" version="502" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175042" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537130" version="502" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537132" version="502" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537134" version="502" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175069" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537136" version="502" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537138" version="502" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175024" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537140" version="502" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175032" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537142" version="502" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175031" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537144" version="502" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537146" version="502" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175027" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537148" version="502" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175035" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537150" version="502" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175054" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537152" version="502" comment="openoffice.org-base is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175026" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537154" version="502" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.5.1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080537078" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537155" version="502" comment="openoffice.org-sdk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080537078" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537157" version="502" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175076" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537159" version="502" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175127" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537161" version="502" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175115" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537163" version="502" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175112" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537165" version="502" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175103" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537167" version="502" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175083" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537169" version="502" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175113" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537171" version="502" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175079" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537173" version="502" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175092" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537175" version="502" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175124" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537177" version="502" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175087" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537179" version="502" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175130" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537181" version="502" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175080" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537183" version="502" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175121" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537185" version="502" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175108" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537187" version="502" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175118" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537189" version="502" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175101" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537191" version="502" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175082" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537193" version="502" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175104" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537195" version="502" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175091" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537197" version="502" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175081" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537199" version="502" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175095" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537201" version="502" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175109" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537203" version="502" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175120" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537205" version="502" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175100" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537207" version="502" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175085" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537209" version="502" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175097" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537211" version="502" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175077" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537213" version="502" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175105" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537215" version="502" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175078" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537217" version="502" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175099" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537219" version="502" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175119" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537221" version="502" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175084" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537223" version="502" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175093" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537225" version="502" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175131" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537227" version="502" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175106" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537229" version="502" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175114" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537231" version="502" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175098" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537233" version="502" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175133" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537235" version="502" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175088" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537237" version="502" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175102" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537239" version="502" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175086" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537241" version="502" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175096" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537243" version="502" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175090" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537245" version="502" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175128" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537247" version="502" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175094" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537249" version="502" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175089" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537251" version="502" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175107" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537253" version="502" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175122" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537255" version="502" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175129" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537257" version="502" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175134" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537259" version="502" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175132" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537261" version="502" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175125" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537263" version="502" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175123" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537265" version="502" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175110" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537267" version="502" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175117" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537269" version="502" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175126" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537271" version="502" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175116" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080537273" version="502" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.5.0" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175111" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080537006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538002" version="502" comment="openoffice.org is earlier than 0:1.1.2-42.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538004" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.2-42.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538006" version="502" comment="openoffice.org-libs is earlier than 0:1.1.2-42.2.0.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538009" version="502" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.5.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080175002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538010" version="502" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.5.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538011" version="502" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.5.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080538012" version="502" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.5.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080538005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544002" version="502" comment="php is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544003" version="502" comment="php is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544004" version="502" comment="php-bcmath is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544005" version="502" comment="php-bcmath is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544006" version="502" comment="php-ldap is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544007" version="502" comment="php-ldap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544008" version="502" comment="php-odbc is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544009" version="502" comment="php-odbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544010" version="502" comment="php-common is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544011" version="502" comment="php-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544012" version="502" comment="php-soap is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544013" version="502" comment="php-soap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544014" version="502" comment="php-imap is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544015" version="502" comment="php-imap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544016" version="502" comment="php-xml is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544017" version="502" comment="php-xml is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544018" version="502" comment="php-devel is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544019" version="502" comment="php-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544020" version="502" comment="php-snmp is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544021" version="502" comment="php-snmp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544022" version="502" comment="php-mysql is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544023" version="502" comment="php-mysql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544024" version="502" comment="php-gd is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544025" version="502" comment="php-gd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544026" version="502" comment="php-xmlrpc is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544027" version="502" comment="php-xmlrpc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544028" version="502" comment="php-pgsql is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544029" version="502" comment="php-pgsql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544030" version="502" comment="php-cli is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544031" version="502" comment="php-cli is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544032" version="502" comment="php-mbstring is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544033" version="502" comment="php-mbstring is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544034" version="502" comment="php-dba is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544035" version="502" comment="php-dba is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544018" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544036" version="502" comment="php-pdo is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544037" version="502" comment="php-pdo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544038" version="502" comment="php-ncurses is earlier than 0:5.1.6-20.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544039" version="502" comment="php-ncurses is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544041" version="502" comment="php is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544042" version="502" comment="php is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544043" version="502" comment="php-odbc is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544044" version="502" comment="php-odbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544045" version="502" comment="php-devel is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544046" version="502" comment="php-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544047" version="502" comment="php-mysql is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544048" version="502" comment="php-mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544049" version="502" comment="php-pgsql is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544050" version="502" comment="php-pgsql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544051" version="502" comment="php-ldap is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544052" version="502" comment="php-ldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544053" version="502" comment="php-imap is earlier than 0:4.3.2-48.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080544006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080544054" version="502" comment="php-imap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545002" version="502" comment="php is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545004" version="502" comment="php-mysql is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545006" version="502" comment="php-ldap is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545008" version="502" comment="php-pear is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080545005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545009" version="502" comment="php-pear is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080545005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545010" version="502" comment="php-devel is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545012" version="502" comment="php-imap is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545014" version="502" comment="php-gd is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545015" version="502" comment="php-gd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545016" version="502" comment="php-snmp is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545017" version="502" comment="php-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545018" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545020" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545021" version="502" comment="php-xmlrpc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545022" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545023" version="502" comment="php-ncurses is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544020" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545024" version="502" comment="php-odbc is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545026" version="502" comment="php-domxml is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080545014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545027" version="502" comment="php-domxml is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080545014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545028" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.22.12" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080545003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080545029" version="502" comment="php-mbstring is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080544017" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547004" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547006" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547008" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547010" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547012" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547014" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547016" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547018" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547020" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.20.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547023" version="502" comment="seamonkey is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547024" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547025" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547026" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547027" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547028" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547029" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547030" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547031" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080547032" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-16.3.el4_6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080104007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080547005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080549002" version="502" comment="firefox is earlier than 0:1.5.0.12-0.19.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080549003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555002" version="502" comment="java-1.4.2-ibm is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555004" version="502" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555006" version="502" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555008" version="502" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555010" version="502" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555012" version="502" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080555014" version="502" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.11-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080132008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080555004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556002" version="503" comment="freetype is earlier than 0:2.2.1-20.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556003" version="503" comment="freetype is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556004" version="503" comment="freetype-devel is earlier than 0:2.2.1-20.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556005" version="503" comment="freetype-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556006" version="503" comment="freetype-demos is earlier than 0:2.2.1-20.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556007" version="503" comment="freetype-demos is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556009" version="503" comment="freetype is earlier than 0:2.1.4-10.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556010" version="503" comment="freetype is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556011" version="503" comment="freetype-utils is earlier than 0:2.1.4-10.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556012" version="503" comment="freetype-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556013" version="503" comment="freetype-devel is earlier than 0:2.1.4-10.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556014" version="503" comment="freetype-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556015" version="503" comment="freetype-demos is earlier than 0:2.1.4-10.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556016" version="503" comment="freetype-demos is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556018" version="503" comment="freetype is earlier than 0:2.1.9-8.el4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556019" version="503" comment="freetype-demos is earlier than 0:2.1.9-8.el4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556020" version="503" comment="freetype-utils is earlier than 0:2.1.9-8.el4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080556021" version="503" comment="freetype-devel is earlier than 0:2.1.9-8.el4.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080556003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080556008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561002" version="502" comment="ruby is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561003" version="502" comment="ruby is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561004" version="502" comment="ruby-ri is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561005" version="502" comment="ruby-ri is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561006" version="502" comment="ruby-irb is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561007" version="502" comment="ruby-irb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561008" version="502" comment="ruby-mode is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561009" version="502" comment="ruby-mode is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561010" version="502" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561011" version="502" comment="ruby-rdoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561012" version="502" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561013" version="502" comment="ruby-tcltk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561014" version="502" comment="ruby-docs is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561015" version="502" comment="ruby-docs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561016" version="502" comment="ruby-devel is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561017" version="502" comment="ruby-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561018" version="502" comment="ruby-libs is earlier than 0:1.8.5-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561019" version="502" comment="ruby-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561021" version="502" comment="ruby is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561022" version="502" comment="ruby is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561023" version="502" comment="ruby-devel is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561024" version="502" comment="ruby-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561025" version="502" comment="ruby-mode is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561026" version="502" comment="ruby-mode is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561027" version="502" comment="ruby-docs is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561028" version="502" comment="ruby-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561029" version="502" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561030" version="502" comment="ruby-tcltk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561031" version="502" comment="irb is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561032" version="502" comment="irb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561033" version="502" comment="ruby-libs is earlier than 0:1.8.1-7.el4_6.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080561006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080561034" version="502" comment="ruby-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562002" version="502" comment="ruby is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562004" version="502" comment="ruby-tcltk is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562006" version="502" comment="ruby-libs is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562008" version="502" comment="ruby-mode is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562010" version="502" comment="irb is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562012" version="502" comment="ruby-devel is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080562014" version="502" comment="ruby-docs is earlier than 0:1.6.8-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080561008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080562003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569002" version="502" comment="xulrunner is earlier than 0:1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569003" version="502" comment="xulrunner is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569004" version="502" comment="xulrunner-devel is earlier than 0:1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569005" version="502" comment="xulrunner-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569006" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569007" version="502" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569008" version="502" comment="yelp is earlier than 0:2.16.0-19.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569009" version="502" comment="yelp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569010" version="502" comment="devhelp is earlier than 0:0.12-17.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569011" version="502" comment="devhelp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569012" version="502" comment="devhelp-devel is earlier than 0:0.12-17.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569013" version="502" comment="devhelp-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080569007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080569014" version="502" comment="firefox is earlier than 0:3.0-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080103002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080569006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080575002" version="502" comment="rdesktop is earlier than 0:1.4.1-6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080575002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080575003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080575003" version="502" comment="rdesktop is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080575002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080576002" version="502" comment="rdesktop is earlier than 0:1.2.0-3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080575002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080576003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080576003" version="502" comment="rdesktop is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080575002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080579002" version="502" comment="vsftpd is earlier than 0:1.2.1-3E.16" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080579003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080579003" version="502" comment="vsftpd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580002" version="502" comment="vim is earlier than 2:7.0.109-4.el5_2.4z" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080580003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580003" version="502" comment="vim is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580004" version="502" comment="vim-common is earlier than 2:7.0.109-4.el5_2.4z" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080580003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580005" version="502" comment="vim-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580006" version="502" comment="vim-minimal is earlier than 2:7.0.109-4.el5_2.4z" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080580003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580007" version="502" comment="vim-minimal is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580008" version="502" comment="vim-X11 is earlier than 2:7.0.109-4.el5_2.4z" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080580003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580009" version="502" comment="vim-X11 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580010" version="502" comment="vim-enhanced is earlier than 2:7.0.109-4.el5_2.4z" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080580003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080580011" version="502" comment="vim-enhanced is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080580006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581002" version="502" comment="bluez-libs is earlier than 0:3.7-1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581003" version="502" comment="bluez-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581004" version="502" comment="bluez-libs-devel is earlier than 0:3.7-1.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581005" version="502" comment="bluez-libs-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581006" version="502" comment="bluez-utils is earlier than 0:3.7-2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581007" version="502" comment="bluez-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581008" version="502" comment="bluez-utils-cups is earlier than 0:3.7-2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581009" version="502" comment="bluez-utils-cups is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581011" version="502" comment="bluez-libs is earlier than 0:2.10-3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581012" version="502" comment="bluez-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581013" version="502" comment="bluez-libs-devel is earlier than 0:2.10-3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581014" version="502" comment="bluez-libs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581015" version="502" comment="bluez-utils is earlier than 0:2.10-2.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581016" version="502" comment="bluez-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581017" version="502" comment="bluez-utils-cups is earlier than 0:2.10-2.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080581008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080581018" version="502" comment="bluez-utils-cups is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080581005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20080583002" version="502" comment="openldap is earlier than 0:2.3.27-8.el5_2.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20080110002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20080583004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst
