<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2011-09-30T09:53:45
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20090002" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0002: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0002-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0002.html" />
          <reference source="CVE" ref_id="CVE-2008-5500" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5500.html" />
          <reference source="CVE" ref_id="CVE-2008-5501" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5501.html" />
          <reference source="CVE" ref_id="CVE-2008-5502" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5502.html" />
          <reference source="CVE" ref_id="CVE-2008-5503" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5503.html" />
          <reference source="CVE" ref_id="CVE-2008-5506" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5506.html" />
          <reference source="CVE" ref_id="CVE-2008-5507" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5507.html" />
          <reference source="CVE" ref_id="CVE-2008-5508" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5508.html" />
          <reference source="CVE" ref_id="CVE-2008-5511" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5511.html" />
          <reference source="CVE" ref_id="CVE-2008-5512" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5512.html" />
          <reference source="CVE" ref_id="CVE-2008-5513" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5513.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2008-5500, CVE-2008-5501, CVE-2008-5502, CVE-2008-5511,
CVE-2008-5512, CVE-2008-5513)

Several flaws were found in the way malformed content was processed. An
HTML mail message containing specially-crafted content could potentially
trick a Thunderbird user into surrendering sensitive information.
(CVE-2008-5503, CVE-2008-5506, CVE-2008-5507)

Note: JavaScript support is disabled by default in Thunderbird; the above
issues are not exploitable unless JavaScript is enabled.

A flaw was found in the way malformed URLs were processed by
Thunderbird. This flaw could prevent various URL sanitization mechanisms
from properly parsing a malicious URL. (CVE-2008-5508)

All Thunderbird users should upgrade to these updated packages, which
resolve these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5500.html">CVE-2008-5500</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5501.html">CVE-2008-5501</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5502.html">CVE-2008-5502</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5503.html">CVE-2008-5503</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5506.html">CVE-2008-5506</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5507.html">CVE-2008-5507</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5508.html">CVE-2008-5508</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5511.html">CVE-2008-5511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5512.html">CVE-2008-5512</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5513.html">CVE-2008-5513</cve>
                <bugzilla href="http://bugzilla.redhat.com/476266" id="476266">CVE-2008-5500 Layout engine crashes - Firefox 2 and 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476267" id="476267">CVE-2008-5501 Layout engine crash - Firefox 3 only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476269" id="476269">CVE-2008-5502 JavaScript engine crash - Firefox 3 only</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476272" id="476272">CVE-2008-5503 Firefox 2  Information stealing via loadBindingDocument</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476278" id="476278">CVE-2008-5506 Firefox XMLHttpRequest 302 response disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476280" id="476280">CVE-2008-5507 Firefox Cross-domain data theft via script redirect error message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476281" id="476281">CVE-2008-5508 Firefox errors parsing URLs with control characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476285" id="476285">CVE-2008-5511 Firefox XSS via XBL bindings to unloaded document</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476287" id="476287">CVE-2008-5512 Firefox JavaScript privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476289" id="476289">CVE-2008-5513 Firefox XSS vulnerabilities in SessionStore</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002002" comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002005" comment="thunderbird is earlier than 0:1.5.0.12-18.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090003" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0003: xen security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0003-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0003.html" />
          <reference source="CVE" ref_id="CVE-2008-4405" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4405.html" />
          <reference source="CVE" ref_id="CVE-2008-4993" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4993.html" />
    
    <description>The xen packages contain the Xen tools and management daemons needed to
manage virtual machines running on Red Hat Enterprise Linux.

Xen was found to allow unprivileged DomU domains to overwrite xenstore
values which should only be changeable by the privileged Dom0 domain. An
attacker controlling a DomU domain could, potentially, use this flaw to
kill arbitrary processes in Dom0 or trick a Dom0 user into accessing the
text console of a different domain running on the same host. This update
makes certain parts of the xenstore tree read-only to the unprivileged DomU
domains. (CVE-2008-4405)

It was discovered that the qemu-dm.debug script created a temporary file in
/tmp in an insecure way. A local attacker in Dom0 could, potentially, use
this flaw to overwrite arbitrary files via a symlink attack. Note: This
script is not needed in production deployments and therefore was removed
and is not shipped with updated xen packages. (CVE-2008-4993)

This update also fixes the following bug:

* xen calculates its running time by adding the hypervisor's up-time to the
hypervisor's boot-time record. In live migrations of para-virtualized
guests, however, the guest would over-write the new hypervisor's boot-time
record with the boot-time of the previous hypervisor. This caused
time-dependent processes on the guests to fail (for example, crond would
fail to start cron jobs). With this update, the new hypervisor's boot-time
record is no longer over-written during live migrations.

All xen users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The Xen host must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4405.html">CVE-2008-4405</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4993.html">CVE-2008-4993</cve>
                <bugzilla href="http://bugzilla.redhat.com/464455" id="464455">timer stops running after live migrate or dom0 reboot &amp; save/restore of a Xen guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464817" id="464817">CVE-2008-4405 xen: Multiple unsafe uses of guest-writable data from xenstore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470795" id="470795">CVE-2008-4993 xen: insecure temporary file use in qemu-dm.debug</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003002" comment="xen is earlier than 0:3.0.3-64.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003004" comment="xen-libs is earlier than 0:3.0.3-64.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003005" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003006" comment="xen-devel is earlier than 0:3.0.3-64.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003007" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090004" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0004: openssl security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0004-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0004.html" />
          <reference source="CVE" ref_id="CVE-2008-5077" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5077.html" />
    
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength,
general purpose, cryptography library.

The Google security team discovered a flaw in the way OpenSSL checked the
verification of certificates. An attacker in control of a malicious server,
or able to effect a "man in the middle" attack, could present a malformed
SSL/TLS signature from a certificate chain to a vulnerable client and
bypass validation. (CVE-2008-5077)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all running OpenSSL client applications must be restarted, or the system
rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5077.html">CVE-2008-5077</cve>
                <bugzilla href="http://bugzilla.redhat.com/476671" id="476671">CVE-2008-5077 OpenSSL Incorrect checks for malformed signatures</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004002" comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004003" comment="openssl097a is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004004" comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004005" comment="openssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004006" comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004007" comment="openssl-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004008" comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004009" comment="openssl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004011" comment="openssl is earlier than 0:0.9.7a-33.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004012" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004013" comment="openssl-perl is earlier than 0:0.9.7a-33.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004014" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004015" comment="openssl-devel is earlier than 0:0.9.7a-33.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004016" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004017" comment="openssl096b is earlier than 0:0.9.6b-16.49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004018" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004020" comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004012" comment="openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004021" comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004014" comment="openssl-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004022" comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004016" comment="openssl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004023" comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004018" comment="openssl096b is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090005" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0005: gnome-vfs, gnome-vfs2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0005.html" />
          <reference source="CVE" ref_id="CVE-2005-0706" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-0706.html" />
    
    <description>GNOME VFS is the GNOME virtual file system. It provides a modular
architecture and ships with several modules that implement support for
various local and remote file systems as well as numerous protocols,
including HTTP, FTP, and others.

A buffer overflow flaw was discovered in the GNOME virtual file system when
handling data returned by CDDB servers. If a user connected to a malicious
CDDB server, an attacker could use this flaw to execute arbitrary code on
the victim's machine. (CVE-2005-0706)

Users of gnome-vfs and gnome-vfs2 are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. All
running GNOME sessions must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-0706.html">CVE-2005-0706</cve>
                <bugzilla href="http://bugzilla.redhat.com/470552" id="470552">CVE-2005-0706 grip,libcdaudio: buffer overflow caused by large amount of CDDB replies</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005004" comment="gnome-vfs2-devel is earlier than 0:2.2.5-2E.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005005" comment="gnome-vfs2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005002" comment="gnome-vfs2 is earlier than 0:2.2.5-2E.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005003" comment="gnome-vfs2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005010" comment="gnome-vfs2-devel is earlier than 0:2.8.2-8.7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005005" comment="gnome-vfs2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005008" comment="gnome-vfs2-smb is earlier than 0:2.8.2-8.7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005009" comment="gnome-vfs2-smb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005007" comment="gnome-vfs2 is earlier than 0:2.8.2-8.7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005003" comment="gnome-vfs2 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090008" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0008: dbus security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0008-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0008.html" />
          <reference source="CVE" ref_id="CVE-2008-3834" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3834.html" />
    
    <description>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial-of-service flaw was discovered in the system for sending messages
between applications. A local user could send a message with a malformed
signature to the bus causing the bus (and, consequently, any process using
libdbus to receive messages) to abort. (CVE-2008-3834)

All users are advised to upgrade to these updated dbus packages, which
contain backported patch which resolve this issue. For the update to take
effect, all running instances of dbus-daemon and all running applications
using libdbus library must be restarted, or the system rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3834.html">CVE-2008-3834</cve>
                <bugzilla href="http://bugzilla.redhat.com/464674" id="464674">CVE-2008-3834 dbus denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090008004" comment="dbus-x11 is earlier than 0:1.0.0-7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090008005" comment="dbus-x11 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090008006" comment="dbus-devel is earlier than 0:1.0.0-7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090008007" comment="dbus-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090008002" comment="dbus is earlier than 0:1.0.0-7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090008003" comment="dbus is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090010" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0010: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0010-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0010.html" />
          <reference source="CVE" ref_id="CVE-2008-2379" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2379.html" />
          <reference source="CVE" ref_id="CVE-2008-3663" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3663.html" />
    
    <description>SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.

Ivan Markovic discovered a cross-site scripting (XSS) flaw in SquirrelMail
caused by insufficient HTML mail sanitization. A remote attacker could send
a specially-crafted HTML mail or attachment that could cause a user's Web
browser to execute a malicious script in the context of the SquirrelMail
session when that email or attachment was opened by the user.
(CVE-2008-2379)

It was discovered that SquirrelMail allowed cookies over insecure
connections (ie did not restrict cookies to HTTPS connections). An attacker
who controlled the communication channel between a user and the
SquirrelMail server, or who was able to sniff the user's network
communication, could use this flaw to obtain the user's session cookie, if
a user made an HTTP request to the server. (CVE-2008-3663)

Note: After applying this update, all session cookies set for SquirrelMail
sessions started over HTTPS connections will have the "secure" flag set.
That is, browsers will only send such cookies over an HTTPS connection. If
needed, you can revert to the previous behavior by setting the
configuration option "$only_secure_cookies" to "false" in SquirrelMail's
/etc/squirrelmail/config.php configuration file.

Users of squirrelmail should upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-12" />
        <updated date="2009-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2379.html">CVE-2008-2379</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3663.html">CVE-2008-3663</cve>
                <bugzilla href="http://bugzilla.redhat.com/464183" id="464183">CVE-2008-3663 squirrelmail: session hijacking - secure flag not set for HTTPS-only cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473877" id="473877">CVE-2008-2379 squirrelmail: XSS issue caused by an insufficient html mail sanitation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010005" comment="squirrelmail is earlier than 0:1.4.8-8.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090011" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0011: lcms security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0011.html" />
          <reference source="CVE" ref_id="CVE-2008-5316" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5316.html" />
          <reference source="CVE" ref_id="CVE-2008-5317" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5317.html" />
    
    <description>Little Color Management System (LittleCMS, or simply "lcms") is a
small-footprint, speed-optimized open source color management engine.

Multiple insufficient input validation flaws were discovered in LittleCMS.
An attacker could use these flaws to create a specially-crafted image file
which could cause an application using LittleCMS to crash, or, possibly,
execute arbitrary code when opened. (CVE-2008-5316, CVE-2008-5317)

Users of lcms should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
lcms library must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5316.html">CVE-2008-5316</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5317.html">CVE-2008-5317</cve>
                <bugzilla href="http://bugzilla.redhat.com/473462" id="473462">CVE-2008-5316 lcms: insufficient input validation in ReadEmbeddedTextTag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473463" id="473463">CVE-2008-5317 lcms: unsigned -> signed integer cast issue in cmsAllocGamma</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090011002" comment="lcms is earlier than 0:1.15-1.2.2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011003" comment="lcms is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090011004" comment="lcms-devel is earlier than 0:1.15-1.2.2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011005" comment="lcms-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090011006" comment="python-lcms is earlier than 0:1.15-1.2.2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011007" comment="python-lcms is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090012" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0012: netpbm security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0012-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0012.html" />
          <reference source="CVE" ref_id="CVE-2007-2721" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2721.html" />
          <reference source="CVE" ref_id="CVE-2008-3520" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3520.html" />
    
    <description>The netpbm package contains a library of functions for editing and
converting between various graphics file formats, including .pbm (portable
bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable
pixmaps), and others.

An input validation flaw and multiple integer overflows were discovered in
the JasPer library providing support for JPEG-2000 image format and used in
the jpeg2ktopam and pamtojpeg2k converters. An attacker could create a
carefully-crafted JPEG file which could cause jpeg2ktopam to crash or,
possibly, execute arbitrary code as the user running jpeg2ktopam.
(CVE-2007-2721, CVE-2008-3520)

All users are advised to upgrade to these updated packages which contain
backported patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-11" />
        <updated date="2009-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2721.html">CVE-2007-2721</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3520.html">CVE-2008-3520</cve>
                <bugzilla href="http://bugzilla.redhat.com/346501" id="346501">CVE-2007-2721 jasper crash in jpc_qcx_getcompparms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461476" id="461476">CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012002" comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012003" comment="netpbm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012006" comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012007" comment="netpbm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012004" comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012005" comment="netpbm-progs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012009" comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012010" comment="netpbm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012013" comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012014" comment="netpbm-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012011" comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012012" comment="netpbm-progs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090013" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0013: avahi security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0013-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0013.html" />
          <reference source="CVE" ref_id="CVE-2008-5081" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5081.html" />
    
    <description>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zeroconf Networking. It facilitates service discovery on
a local network. Avahi and Avahi-aware applications allow you to plug your
computer into a network and, with no configuration, view other people to
chat with, see printers to print to, and find shared files on other computers.

Hugo Dias discovered a denial of service flaw in avahi-daemon. A remote
attacker on the same local area network (LAN) could send a
specially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemon
to exit unexpectedly due to a failed assertion check. (CVE-2008-5081)

All users are advised to upgrade to these updated packages, which contain a
backported patch which resolves this issue. After installing the update,
avahi-daemon will be restarted automatically.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-12" />
        <updated date="2009-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5081.html">CVE-2008-5081</cve>
                <bugzilla href="http://bugzilla.redhat.com/475964" id="475964">CVE-2008-5081 avahi: avahi-daemon DoS (application abort) via packet with source port 0</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013022" comment="avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013023" comment="avahi-compat-howl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013018" comment="avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013019" comment="avahi-glib-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013002" comment="avahi is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013003" comment="avahi is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013010" comment="avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013011" comment="avahi-compat-howl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013004" comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013005" comment="avahi-compat-libdns_sd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013008" comment="avahi-glib is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013009" comment="avahi-glib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013020" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013021" comment="avahi-compat-libdns_sd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013014" comment="avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013015" comment="avahi-qt3 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013012" comment="avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013013" comment="avahi-qt3-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013006" comment="avahi-tools is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013007" comment="avahi-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013016" comment="avahi-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013017" comment="avahi-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090014" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0014: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0014-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0014.html" />
          <reference source="CVE" ref_id="CVE-2008-3275" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3275.html" />
          <reference source="CVE" ref_id="CVE-2008-4933" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4933.html" />
          <reference source="CVE" ref_id="CVE-2008-4934" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4934.html" />
          <reference source="CVE" ref_id="CVE-2008-5025" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5025.html" />
          <reference source="CVE" ref_id="CVE-2008-5029" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5029.html" />
          <reference source="CVE" ref_id="CVE-2008-5300" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5300.html" />
          <reference source="CVE" ref_id="CVE-2008-5702" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5702.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* the sendmsg() function in the Linux kernel did not block during UNIX
socket garbage collection. This could, potentially, lead to a local denial
of service. (CVE-2008-5300, Important)

* when fput() was called to close a socket, the __scm_destroy() function in
the Linux kernel could make indirect recursive calls to itself. This could,
potentially, lead to a local denial of service. (CVE-2008-5029, Important)

* a deficiency was found in the Linux kernel virtual file system (VFS)
implementation. This could allow a local, unprivileged user to make a
series of file creations within deleted directories, possibly causing a
denial of service. (CVE-2008-3275, Moderate)

* a buffer underflow flaw was found in the Linux kernel IB700 SBC watchdog
timer driver. This deficiency could lead to a possible information leak. By
default, the "/dev/watchdog" device is accessible only to the root user.
(CVE-2008-5702, Low)

* the hfs and hfsplus file systems code failed to properly handle corrupted
data structures. This could, potentially, lead to a local denial of
service. (CVE-2008-4933, CVE-2008-5025, Low)

* a flaw was found in the hfsplus file system implementation. This could,
potentially, lead to a local denial of service when write operations were
performed. (CVE-2008-4934, Low)

This update also fixes the following bugs:

* when running Red Hat Enterprise Linux 4.6 and 4.7 on some systems running
Intel® CPUs, the cpuspeed daemon did not run, preventing the CPU speed from
being changed, such as not being reduced to an idle state when not in use.

* mmap() could be used to gain access to beyond the first megabyte of RAM,
due to insufficient checks in the Linux kernel code. Checks have been added
to prevent this.

* attempting to turn keyboard LEDs on and off rapidly on keyboards with
slow keyboard controllers, may have caused key presses to fail.

* after migrating a hypervisor guest, the MAC address table was not
updated, causing packet loss and preventing network connections to the
guest. Now, a gratuitous ARP request is sent after migration. This
refreshes the ARP caches, minimizing network downtime.

* writing crash dumps with diskdump may have caused a kernel panic on
Non-Uniform Memory Access (NUMA) systems with certain memory
configurations.

* on big-endian systems, such as PowerPC, the getsockopt() function
incorrectly returned 0 depending on the parameters passed to it when the
time to live (TTL) value equaled 255, possibly causing memory corruption
and application crashes.

* a problem in the kernel packages provided by the RHSA-2008:0508 advisory
caused the Linux kernel's built-in memory copy procedure to return the
wrong error code after recovering from a page fault on AMD64 and Intel 64
systems. This may have caused other Linux kernel functions to return wrong
error codes.

* a divide-by-zero bug in the Linux kernel process scheduler, which may
have caused kernel panics on certain systems, has been resolved.

* the netconsole kernel module caused the Linux kernel to hang when slave
interfaces of bonded network interfaces were started, resulting in a system
hang or kernel panic when restarting the network.

* the "/proc/xen/" directory existed even if systems were not running Red
Hat Virtualization. This may have caused problems for third-party software
that checks virtualization-ability based on the existence of "/proc/xen/".
Note: this update will remove the "/proc/xen/" directory on systems not
running Red Hat Virtualization.

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-14" />
        <updated date="2009-01-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3275.html">CVE-2008-3275</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4933.html">CVE-2008-4933</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4934.html">CVE-2008-4934</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5025.html">CVE-2008-5025</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5029.html">CVE-2008-5029</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5300.html">CVE-2008-5300</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5702.html">CVE-2008-5702</cve>
                <bugzilla href="http://bugzilla.redhat.com/248710" id="248710">Local keyboard DoS through LED switching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457858" id="457858">CVE-2008-3275 Linux kernel local filesystem DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460862" id="460862">kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-4.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469631" id="469631">CVE-2008-4933 kernel: hfsplus: fix Buffer overflow with a corrupted image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469640" id="469640">CVE-2008-4934 kernel: hfsplus: check read_mapping_page() return value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469891" id="469891">lost packets when live migrating (RHEL4 XEN)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470034" id="470034">HP-Japan: RHEL4.6 diskdump fails when NUMA is on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470196" id="470196">getsockopt() returning incorrectly in PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470201" id="470201">CVE-2008-5029 kernel: Unix sockets kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470769" id="470769">CVE-2008-5025 kernel: hfs: fix namelength memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471015" id="471015">RHSA-2008:0508 linux-2.6.9-x86_64-copy_user-zero-tail.patch broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471222" id="471222">erroneous load balancing for isolated CPUs leads to divide-by-zero panic in find_busiest_group()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471391" id="471391">netconsole hang the system on ifenslave operation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473259" id="473259">CVE-2008-5300 kernel: fix soft lockups/OOM issues with unix socket garbage collector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475733" id="475733">CVE-2008-5702 kernel: watchdog: ib700wdt.c - buffer_underflow bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476534" id="476534">Xen balloon driver on RHEL4 x86_64 with 2.6.9-78.0.1.ELsmp</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014002" comment="kernel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014022" comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014004" comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014012" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014018" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014008" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014006" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014016" comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014014" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014010" comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090015" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0015: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0015-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0015.html" />
          <reference source="CVE" ref_id="CVE-2008-2086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2086.html" />
          <reference source="CVE" ref_id="CVE-2008-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5339.html" />
          <reference source="CVE" ref_id="CVE-2008-5344" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5344.html" />
          <reference source="CVE" ref_id="CVE-2008-5345" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5345.html" />
          <reference source="CVE" ref_id="CVE-2008-5347" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5347.html" />
          <reference source="CVE" ref_id="CVE-2008-5348" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5348.html" />
          <reference source="CVE" ref_id="CVE-2008-5350" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5350.html" />
          <reference source="CVE" ref_id="CVE-2008-5352" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5352.html" />
          <reference source="CVE" ref_id="CVE-2008-5353" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5353.html" />
          <reference source="CVE" ref_id="CVE-2008-5354" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5354.html" />
          <reference source="CVE" ref_id="CVE-2008-5359" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5359.html" />
          <reference source="CVE" ref_id="CVE-2008-5360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5360.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These are
summarized in the "Security Alerts" from IBM. 

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR3 Java release.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-13" />
        <updated date="2009-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2086.html">CVE-2008-2086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5339.html">CVE-2008-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5344.html">CVE-2008-5344</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5345.html">CVE-2008-5345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5347.html">CVE-2008-5347</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5348.html">CVE-2008-5348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5350.html">CVE-2008-5350</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5352.html">CVE-2008-5352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5353.html">CVE-2008-5353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5354.html">CVE-2008-5354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5359.html">CVE-2008-5359</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5360.html">CVE-2008-5360</cve>
                <bugzilla href="http://bugzilla.redhat.com/472201" id="472201">CVE-2008-5350 OpenJDK allows to list files within the user home directory (6484091)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472208" id="472208">CVE-2008-5347 OpenJDK applet privilege escalation via JAX package access (6592792)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472209" id="472209">CVE-2008-5348 OpenJDK Denial-Of-Service in kerberos authentication (6588160)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472211" id="472211">CVE-2008-5360 OpenJDK temporary files have guessable file names (6721753)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472212" id="472212">CVE-2008-5359 OpenJDK Buffer overflow in image processing (6726779)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472224" id="472224">CVE-2008-5353 OpenJDK calendar object deserialization allows privilege escalation (6734167)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472228" id="472228">CVE-2008-5354 OpenJDK Privilege escalation in command line applications (6733959)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472233" id="472233">CVE-2008-5352 OpenJDK Jar200 Decompression buffer overflow (6755943)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474556" id="474556">CVE-2008-2086 Java Web Start File Inclusion via System Properties Override</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474772" id="474772">CVE-2008-5339 JavaWebStart allows unauthorized network connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474792" id="474792">CVE-2008-5344 Java WebStart unprivileged local file and network access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474793" id="474793">CVE-2008-5345 JRE allows unauthorized file access and connections to localhost</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015010" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015011" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015008" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015006" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015007" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015016" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015017" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015004" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015005" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015012" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015013" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090015014" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015015" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090016" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0016: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0016-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0016.html" />
          <reference source="CVE" ref_id="CVE-2008-2086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2086.html" />
          <reference source="CVE" ref_id="CVE-2008-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5339.html" />
          <reference source="CVE" ref_id="CVE-2008-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5340.html" />
          <reference source="CVE" ref_id="CVE-2008-5341" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5341.html" />
          <reference source="CVE" ref_id="CVE-2008-5342" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5342.html" />
          <reference source="CVE" ref_id="CVE-2008-5343" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5343.html" />
          <reference source="CVE" ref_id="CVE-2008-5344" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5344.html" />
          <reference source="CVE" ref_id="CVE-2008-5345" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5345.html" />
          <reference source="CVE" ref_id="CVE-2008-5346" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5346.html" />
          <reference source="CVE" ref_id="CVE-2008-5348" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5348.html" />
          <reference source="CVE" ref_id="CVE-2008-5349" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5349.html" />
          <reference source="CVE" ref_id="CVE-2008-5350" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5350.html" />
          <reference source="CVE" ref_id="CVE-2008-5351" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5351.html" />
          <reference source="CVE" ref_id="CVE-2008-5352" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5352.html" />
          <reference source="CVE" ref_id="CVE-2008-5353" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5353.html" />
          <reference source="CVE" ref_id="CVE-2008-5354" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5354.html" />
          <reference source="CVE" ref_id="CVE-2008-5356" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5356.html" />
          <reference source="CVE" ref_id="CVE-2008-5357" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5357.html" />
          <reference source="CVE" ref_id="CVE-2008-5359" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5359.html" />
          <reference source="CVE" ref_id="CVE-2008-5360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5360.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These are
summarized in the "Security Alerts" from IBM. 

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR9 Java release.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-13" />
        <updated date="2009-01-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2086.html">CVE-2008-2086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5339.html">CVE-2008-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5340.html">CVE-2008-5340</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5341.html">CVE-2008-5341</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5342.html">CVE-2008-5342</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5343.html">CVE-2008-5343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5344.html">CVE-2008-5344</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5345.html">CVE-2008-5345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5346.html">CVE-2008-5346</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5348.html">CVE-2008-5348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5349.html">CVE-2008-5349</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5350.html">CVE-2008-5350</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5351.html">CVE-2008-5351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5352.html">CVE-2008-5352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5353.html">CVE-2008-5353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5354.html">CVE-2008-5354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5356.html">CVE-2008-5356</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5357.html">CVE-2008-5357</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5359.html">CVE-2008-5359</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5360.html">CVE-2008-5360</cve>
                <bugzilla href="http://bugzilla.redhat.com/472201" id="472201">CVE-2008-5350 OpenJDK allows to list files within the user home directory (6484091)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472206" id="472206">CVE-2008-5349 OpenJDK RSA public key length denial-of-service (6497740)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472209" id="472209">CVE-2008-5348 OpenJDK Denial-Of-Service in kerberos authentication (6588160)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472211" id="472211">CVE-2008-5360 OpenJDK temporary files have guessable file names (6721753)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472212" id="472212">CVE-2008-5359 OpenJDK Buffer overflow in image processing (6726779)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472213" id="472213">CVE-2008-5351 OpenJDK UTF-8 decoder accepts non-shortest form sequences (4486841)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472218" id="472218">CVE-2008-5356 OpenJDK Font processing vulnerability (6733336)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472224" id="472224">CVE-2008-5353 OpenJDK calendar object deserialization allows privilege escalation (6734167)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472228" id="472228">CVE-2008-5354 OpenJDK Privilege escalation in command line applications (6733959)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472231" id="472231">CVE-2008-5357 OpenJDK Truetype Font processing vulnerability (6751322)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472233" id="472233">CVE-2008-5352 OpenJDK Jar200 Decompression buffer overflow (6755943)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474556" id="474556">CVE-2008-2086 Java Web Start File Inclusion via System Properties Override</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474772" id="474772">CVE-2008-5339 JavaWebStart allows unauthorized network connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474773" id="474773">CVE-2008-5340 Java WebStart privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474786" id="474786">CVE-2008-5341 Java Web Start exposes username and the pathname of the JWS cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474789" id="474789">CVE-2008-5342 Java Web Start BasicService displays local files in the browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474790" id="474790">CVE-2008-5343 Java WebStart allows hidden code privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474792" id="474792">CVE-2008-5344 Java WebStart unprivileged local file and network access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474793" id="474793">CVE-2008-5345 JRE allows unauthorized file access and connections to localhost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474794" id="474794">CVE-2008-5346 JRE allows unauthorized memory read access via a crafted ZIP file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016006" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016008" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016009" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016014" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016016" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016017" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016004" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016010" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016011" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090016012" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.9-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016013" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090018" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0018: xterm security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0018.html" />
          <reference source="CVE" ref_id="CVE-2008-2383" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2383.html" />
    
    <description>The xterm program is a terminal emulator for the X Window System.

A flaw was found in the xterm handling of Device Control Request Status
String (DECRQSS) escape sequences. An attacker could create a malicious
text file (or log entry, if unfiltered) that could run arbitrary commands
if read by a victim inside an xterm window. (CVE-2008-2383)

All xterm users are advised to upgrade to the updated package, which
contains a backported patch to resolve this issue. All running instances of
xterm must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2383.html">CVE-2008-2383</cve>
                <bugzilla href="http://bugzilla.redhat.com/478888" id="478888">CVE-2008-2383 xterm: arbitrary command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018002" comment="xterm is earlier than 0:215-5.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018003" comment="xterm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018005" comment="xterm is earlier than 0:179-11.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018006" comment="xterm is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018008" comment="xterm is earlier than 0:192-8.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018006" comment="xterm is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090020" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0020: bind security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0020-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0020.html" />
          <reference source="CVE" ref_id="CVE-2009-0025" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0025.html" />
    
    <description>BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.

A flaw was discovered in the way BIND checked the return value of the
OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone
could present a malformed DSA certificate and bypass proper certificate
validation, allowing spoofing attacks. (CVE-2009-0025)

For users of Red Hat Enterprise Linux 3 this update also addresses a bug
which can cause BIND to occasionally exit with an assertion failure.

All BIND users are advised to upgrade to the updated package, which
contains a backported patch to resolve this issue. After installing the
update, BIND daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-08" />
        <updated date="2009-01-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0025.html">CVE-2009-0025</cve>
                <bugzilla href="http://bugzilla.redhat.com/461047" id="461047">named dies due to assertion failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478984" id="478984">CVE-2009-0025 bind: DSA_do_verify() returns check issue</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020010" comment="bind-utils is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020011" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020008" comment="bind-chroot is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020009" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020006" comment="bind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020007" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020004" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020005" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020016" comment="bind-sdb is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020017" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020002" comment="bind is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020012" comment="bind-libs is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020013" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020014" comment="caching-nameserver is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020015" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020027" comment="bind-chroot is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020028" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020023" comment="bind-devel is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020024" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020021" comment="bind-utils is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020022" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020019" comment="bind is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020020" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020025" comment="bind-libs is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020026" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020033" comment="bind-chroot is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020028" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020032" comment="bind-devel is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020024" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020031" comment="bind-utils is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020022" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020030" comment="bind is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020020" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020034" comment="bind-libs is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020026" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090045" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:0382: libvirt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0382-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0382.html" />
          <reference source="CVE" ref_id="CVE-2008-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5086.html" />
          <reference source="CVE" ref_id="CVE-2009-0036" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0036.html" />
    
    <description>libvirt is a C API for managing and interacting with the virtualization
capabilities of Linux and other operating systems. libvirt also provides
tools for remotely managing virtualized systems.

The libvirtd daemon was discovered to not properly check user connection
permissions before performing certain privileged actions, such as
requesting migration of an unprivileged guest domain to another system. A
local user able to establish a read-only connection to libvirtd could use
this flaw to perform actions that should be restricted to read-write
connections. (CVE-2008-5086)

libvirt_proxy, a setuid helper application allowing non-privileged users to
communicate with the hypervisor, was discovered to not properly validate
user requests. Local users could use this flaw to cause a stack-based
buffer overflow in libvirt_proxy, possibly allowing them to run arbitrary
code with root privileges. (CVE-2009-0036)

All users are advised to upgrade to these updated packages, which contain
backported patches which resolve these issues. After installing the update,
libvirtd must be restarted manually (for example, by issuing a "service
libvirtd restart" command), and guest systems rebooted, for this change to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2011 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2011-05-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5086.html">CVE-2008-5086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0036.html">CVE-2009-0036</cve>
                <bugzilla href="http://bugzilla.redhat.com/476560" id="476560">CVE-2008-5086 libvirt: missing checks for read-only connection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484947" id="484947">CVE-2009-0036 libvirt: libvirt_proxy buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090045006" comment="libvirt-devel is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090045007" comment="libvirt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090045002" comment="libvirt is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090045003" comment="libvirt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090045004" comment="libvirt-python is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090045005" comment="libvirt-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090046" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0046: ntp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0046-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0046.html" />
          <reference source="CVE" ref_id="CVE-2009-0021" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0021.html" />
    
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A flaw was discovered in the way the ntpd daemon checked the return value
of the OpenSSL EVP_VerifyFinal function. On systems using NTPv4
authentication, this could lead to an incorrect verification of
cryptographic signatures, allowing time-spoofing attacks. (CVE-2009-0021)

Note: This issue only affects systems that have enabled NTP authentication.
By default, NTP authentication is not enabled.

All ntp users are advised to upgrade to the updated packages, which contain
a backported patch to resolve this issue. After installing the update, the
ntpd daemon will restart automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-29" />
        <updated date="2009-01-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0021.html">CVE-2009-0021</cve>
                <bugzilla href="http://bugzilla.redhat.com/476807" id="476807">CVE-2009-0021 ntp incorrectly checks for malformed signatures</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046002" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046003" comment="ntp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046005" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046006" comment="ntp is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090057" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0057: squirrelmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0057-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0057.html" />
          <reference source="CVE" ref_id="CVE-2009-0030" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0030.html" />
          <reference source="CVE" ref_id="CVE-2009-1580" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1580.html" />
    
    <description>SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.

The Red Hat SquirrelMail packages provided by the RHSA-2009:0010 advisory
introduced a session handling flaw. Users who logged back into SquirrelMail
without restarting their web browsers were assigned fixed session
identifiers. A remote attacker could make use of that flaw to hijack user
sessions. (CVE-2009-0030)

SquirrelMail users should upgrade to this updated package, which contains a
patch to correct this issue. As well, all users who used affected versions
of SquirrelMail should review their preferences.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-19" />
        <updated date="2009-01-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0030.html">CVE-2009-0030</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1580.html">CVE-2009-1580</cve>
                <bugzilla href="http://bugzilla.redhat.com/480224" id="480224">Squirrelmail session management broken by security backport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480488" id="480488">CVE-2009-0030 squirrelmail: session management flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090057002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090057005" comment="squirrelmail is earlier than 0:1.4.8-9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090057008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090205" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:0205: dovecot security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0205-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0205.html" />
          <reference source="CVE" ref_id="CVE-2008-4577" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4577.html" />
          <reference source="CVE" ref_id="CVE-2008-4870" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4870.html" />
    
    <description>Dovecot is an IMAP server for Linux and UNIX-like systems, primarily
written with security in mind.

A flaw was found in Dovecot's ACL plug-in. The ACL plug-in treated negative
access rights as positive rights, which could allow an attacker to bypass
intended access restrictions. (CVE-2008-4577)

A password disclosure flaw was found with Dovecot's configuration file. If
a system had the "ssl_key_password" option defined, any local user could
view the SSL key password. (CVE-2008-4870)

Note: This flaw did not allow the attacker to acquire the contents of the
SSL key. The password has no value without the key file which arbitrary
users should not have read access to.

To better protect even this value, however, the dovecot.conf file now
supports the "!include_try" directive. The ssl_key_password option should
be moved from dovecot.conf to a new file owned by, and only readable and
writable by, root (ie 0600). This file should be referenced from
dovecot.conf by setting the "!include_try [/path/to/password/file]" option.

Additionally, this update addresses the following bugs:

* the dovecot init script -- /etc/rc.d/init.d/dovecot -- did not check if
the dovecot binary or configuration files existed. It also used the wrong
pid file for checking the dovecot service's status. This update includes a
new init script that corrects these errors.

* the %files section of the dovecot spec file did not include "%dir
%{ssldir}/private". As a consequence, the /etc/pki/private/ directory was
not owned by dovecot. (Note: files inside /etc/pki/private/ were and are
owned by dovecot.) With this update, the missing line has been added to the
spec file, and the noted directory is now owned by dovecot.

* in some previously released versions of dovecot, the authentication
process accepted (and passed along un-escaped) passwords containing
characters that had special meaning to dovecot's internal protocols. This
updated release prevents such passwords from being passed back, instead
returning the error, "Attempted login with password having illegal chars".

Note: dovecot versions previously shipped with Red Hat Enterprise Linux 5
did not allow this behavior. This update addresses the issue above but said
issue was only present in versions of dovecot not previously included with
Red Hat Enterprise Linux 5.

Users of dovecot are advised to upgrade to this updated package, which
addresses these vulnerabilities and resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-20" />
        <updated date="2009-01-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4577.html">CVE-2008-4577</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4870.html">CVE-2008-4870</cve>
                <bugzilla href="http://bugzilla.redhat.com/238016" id="238016">Wrong init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436287" id="436287">dovecot.conf is world readable - possible password exposure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439369" id="439369">new dovecot security issues from the dovecot site</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448089" id="448089">dovecot should own /etc/pki/dovecot/private directory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467436" id="467436">CVE-2008-4577 dovecot: incorrect handling of negative rights in the ACL plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469659" id="469659">CVE-2008-4870 dovecot: ssl_key_password disclosure due to an insecure dovecot.conf permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090205002" comment="dovecot is earlier than 0:1.0.7-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090205003" comment="dovecot is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090225" version="504" class="patch">
      <metadata>
        <title>RHSA-2009:0225: Red Hat Enterprise Linux 5.3 kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0225-03" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0225.html" />
          <reference source="CVE" ref_id="CVE-2008-5029" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5029.html" />
          <reference source="CVE" ref_id="CVE-2008-5079" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5079.html" />
          <reference source="CVE" ref_id="CVE-2008-5182" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5182.html" />
          <reference source="CVE" ref_id="CVE-2008-5300" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5300.html" />
    
    <description>The Linux kernel (the core of the Linux operating system)

These updated packages contain 730 bug fixes and enhancements for the Linux
kernel. Space precludes a detailed description of each of these changes in
this advisory and users are therefore directed to the release notes for Red
Hat Enterprise Linux 5.3 for information on 97 of the most significant of
these changes. 

Details of three security-related bug fixes are set out below, along with
notes on other broad categories of change not covered in the release notes.
For more detailed information on specific bug fixes or enhancements, please
consult the Bugzilla numbers listed in this advisory.

* when fput() was called to close a socket, the __scm_destroy() function  
in the Linux kernel could make indirect recursive calls to itself. This  
could, potentially, lead to a denial of service issue. (CVE-2008-5029,  
Important)

* a flaw was found in the Asynchronous Transfer Mode (ATM) subsystem. A
local, unprivileged user could use the flaw to listen on the same socket
more than once, possibly causing a denial of service. (CVE-2008-5079,
Important)

* a race condition was found in the Linux kernel "inotify" watch removal
and umount implementation. This could allow a local, unprivileged user  
to cause a privilege escalation or a denial of service. (CVE-2008-5182,  
Important)

* Bug fixes and enhancements are provided for:

* support for specific NICs, including products from the following
manufacturers:
Broadcom
Chelsio
Cisco
Intel
Marvell
NetXen
Realtek
Sun

* Fiber Channel support, including support for Qlogic qla2xxx,
qla4xxx, and qla84xx HBAs and the FCoE, FCP, and zFCP protocols.

* support for various CPUs, including:
AMD Opteron processors with 45 nm SOI ("Shanghai")
AMD Turion Ultra processors
Cell processors
Intel Core i7 processors

* Xen support, including issues specific to the IA64 platform, systems
using AMD processors, and Dell Optiplex GX280 systems

* ext3, ext4, GFS2, NFS, and SPUFS

* Infiniband (including eHCA, eHEA, and IPoIB) support

* common I/O (CIO), direct I/O (DIO), and queued direct I/O (qdio) support

* the kernel distributed lock manager (DLM)

* hardware issues with: SCSI, IEEE 1394 (FireWire), RAID (including issues
specific to Adaptec controllers), SATA (including NCQ), PCI, audio, serial
connections, tape-drives, and USB

* ACPI, some of a general nature and some related to specific hardware
including: certain Lenovo Thinkpad notebooks, HP DC7700 systems, and
certain machines based on Intel Centrino processor technology.

* CIFS, including Kerberos support and a tech-preview of DFS support

* networking support, including IPv6, PPPoE, and IPSec

* support for Intel chipsets, including:
Intel Cantiga chipsets
Intel Eagle Lake chipsets
Intel i915 chipsets
Intel i965 chipsets
Intel Ibex Peak chipsets
Intel chipsets offering QuickPath Interconnects (QPI)

* device mapping issues, including some in device mapper itself

* various issues specific to IA64 and PPC

* CCISS, including support for Compaq SMART Array controllers P711m and
P712m and other new hardware

* various issues affecting specific HP systems, including:
DL785G5
XW4800
XW8600
XW8600
XW9400

* IOMMU support, including specific
issues with AMD and IBM Calgary hardware

* the audit subsystem

* DASD support

* iSCSI support, including issues specific to Chelsio T3 adapters

* LVM issues

* SCTP management information base (MIB) support

* issues with: autofs, kdump, kobject_add, libata, lpar, ptrace, and utrace

* IBM Power platforms using Enhanced I/O Error Handling (EEH)

* EDAC issues for AMD K8 and Intel i5000

* ALSA, including support for new hardware

* futex support

* hugepage support

* Intelligent Platform Management Interface (IPMI) support

* issues affecting NEC/Stratus servers

* OFED support

* SELinux 

* various Virtio issues

All users are advised to upgrade to these updated packages, which resolve
these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-20" />
        <updated date="2009-01-20" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5029.html">CVE-2008-5029</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5079.html">CVE-2008-5079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5182.html">CVE-2008-5182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5300.html">CVE-2008-5300</cve>
                <bugzilla href="http://bugzilla.redhat.com/228836" id="228836">acpi processor  module displays errors if hyperthreading disabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231369" id="231369">GFS2 will panic if you misspell any mount options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/236750" id="236750">When bonding is used and IPV6 is enabled the message of 'kernel: bond0: duplicate address detected!' is output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239604" id="239604">[RHEL5] console: kobject_add failed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243526" id="243526">IPv6 default route does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244135" id="244135">audit tty input</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249726" id="249726">Misspellings in RPM description, suggested clarifications</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250104" id="250104">RHEL5 Kernel patches for blktap statistics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/254195" id="254195">use after free in nlm subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/350281" id="350281">IPSec Packet has no Non-ESP marker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/370471" id="370471">[RFE] Add support for Wacom PTZ-431W to kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/376831" id="376831">Read from /proc/ppc64/rtas/error_log does not honor O_NONBLOCK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382491" id="382491">duplicate packet from ipt_CLUSTERIP module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/390601" id="390601">[RHEL5] EDAC k8 MC0: extended error code: GART error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/406051" id="406051">Marvell NIC using skge driver loses promiscuous mode on rewiring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/412691" id="412691">kernel-xen panic when X shuts down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/420961" id="420961">Driver sky2 lost support for Marvell 88E8056 network controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/423521" id="423521">memory leak on size-8192 buckets with NFSV4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425341" id="425341">Please add vscnprintf and down_write_trylock to KABI Whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425955" id="425955">resize2fs online resize fails with small journal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426096" id="426096">Xenoprof check_ctrs/start/stop fixes for intel family 6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426895" id="426895">fix default route doesn't work.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428275" id="428275">Need EOE (End of Event) audit message sent from kernel.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428277" id="428277">Audit subsystem SIGUSR2 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428696" id="428696">nVidia MCP55 MCP55 Ethernet (rev a3) not functional on kernel 2.6.18-53.1.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428720" id="428720">[RHEL5 U2] Connectathon RHEL5 client to RHEL4 server, Connectathon failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429054" id="429054">soft lockup while unmounting a read-only filesystem with errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429142" id="429142">RHEL5.2: ecryptfs oops after lower persistent file creation failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429337" id="429337">Make dm interfaces available for external modules.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429941" id="429941">[RHEL5 U2] Audit fails to shutdown properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429950" id="429950">[firewire] unable to use disk (giving up on config rom)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429951" id="429951">[firewire] unable to use disk (fw_sbp2: failed to login to ...)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430300" id="430300">[firewire] ohci iso receive support incomplete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431183" id="431183">utrace: PTRACE_POKEUSR_AREA corrupts ACR0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431365" id="431365">SCSI IO errors do not propagate properly with certain SCSI devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431868" id="431868">mounting CIFS subshare doesn't autoconvert prepath delimiters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432057" id="432057">GFS2: d_doio stuck in readv() waiting for pagelock.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432867" id="432867">memory corruption due to portmap call succeeding after parent rpc_clnt has been freed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433661" id="433661">kernel panic with voip traffic (h323)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434538" id="434538">sr #1768018 : numlock led does not reflect the status of numlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434800" id="434800">xenkbd can crash when probe fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434998" id="434998">utrace: ERESTARTSYS from calling a function from a debugger</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435110" id="435110">fix up remaining sctp MIB problems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435115" id="435115">kernel freezes when running script which features ecryptfs parts of kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435144" id="435144">whitelist: iounmap(ia64) - Failed ABI dependencies for IA64 mpt SCSI drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435291" id="435291">LTC41974-Pages of a memory mapped NFS file get corrupted.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436004" id="436004">50-75 % drop in nfs-server rewrite performance compared to rhel 4.6+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436068" id="436068">[Areca 5.3 feat] Update arcmsr to version 1.20.00.15.RH1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436686" id="436686">tg3.c does not build on sparc with > 2.6.18-53.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436966" id="436966">e1000_clean_tx_irq: Detected Tx Unit Hang - 82546EB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437129" id="437129">Rpm install fails due to missing symbols required in myri10ge-kmod x86_64 rpm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437479" id="437479">remove extraneous error field from nfs_readdir_descriptor_t</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437544" id="437544">fix bad merge in nfs3_write_done and nfs3_commit_done</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437579" id="437579">batch kprobe unregister</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437803" id="437803">gfs2 crash - BUG: unable to handle kernel NULL pointer dereference at virtual address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437882" id="437882">utrace: orig_rax 0x00000000ffffffff not recognized as -1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437958" id="437958">/proc/&lt;pid>/environ not always accessible when receiving PTRACE_EVENT_EXIT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438153" id="438153">Poor LVM mirroring performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438230" id="438230">ia64: suspecious compile warning in brew</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438423" id="438423">backport patch to RHEL5 have it flip to synchronous writes when there is a write error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438761" id="438761">LTC:5.4:201049:DM-MP SCSI Hardware Handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439193" id="439193">Assertion failure in journal_next_log_block</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439194" id="439194">Assertion failure in journal_start() at fs/jbd/transaction.c:274: 'handle->h_transaction->t_journal == journal'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439899" id="439899">[RFE] Add uvcvideo module to the kernel.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439917" id="439917">kernel: splice: fix bad unlock_page() in error case [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439918" id="439918">kernel: dio: zero struct dio with kzalloc instead of manually [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440261" id="440261">xen/ia64 asm missing srlz instruction</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440413" id="440413">ecryptfs module incorrectly checks error codes in process_request_key_err</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440506" id="440506">panic in aoe:aoecmd_ata_rsp during direct I/O to lvm [snap,mirror,stripe]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441615" id="441615">HP DC7700 ACPI problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441640" id="441640">RHEL 5.1 will incorrectly mark SCSI devices as offline due to improper error handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441716" id="441716">Fake ARP dropped after migration leading to loss of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441832" id="441832">mptscsi race between hotremove and mptscsih_bus_reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442426" id="442426">do not limit locked memory when RLIMIT_MEMLOCK is RLIM_INFINITY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442577" id="442577">Backport fix for possible data corruption in mark_buffer_dirty on SMP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442661" id="442661">[5.2][kdump][xen] crash failed to read vmcore from Dom0 Kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442723" id="442723">Xen Support more than 16 disk devices (kernel)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442736" id="442736">launching too many guests panics with "No available IRQ to bind to: increase NR_IRQS!"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442820" id="442820">IPV6DOD: ESP with 3des-cbc for encrypt and authentication set to "null"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442906" id="442906">libata: sata_nv - disable ADMA by default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442991" id="442991">Include xenpv-driver in bare metal kernel rpm.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443043" id="443043">fix setuid/setgid clearing by knfsd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443395" id="443395">cp -p does not copy mtime to CIFS share</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443522" id="443522">ls shows two /proc/[pid]/limits files for every process</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443618" id="443618">[REG][Xen][5.2beta] cannot open a vmcore of xen-kdump with crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443627" id="443627">kernel dm snapshot: PPC64: kernel OOPS during activation of snapshot with small chunksize</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443645" id="443645">ST Driver causing kernel panic condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443853" id="443853">RHEL 5.3 NULL pointer dereferenced in powernowk8_init</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443896" id="443896">RFE: [Ext4 enabler] backport vfs helpers to facilitate ext4 backport and testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444582" id="444582">IPV6DOD: all MCAST_* socket options fail  with 32-bit app, 64-bit kernel due to padding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444589" id="444589">xentop - incompatibility between HV and userspace toolset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444611" id="444611">kernel doesn't honor ADDR_NO_RANDOMIZE for stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444759" id="444759">high I/O wait using 3w-9xxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444776" id="444776">iBFT target info not parsed properly by the iscsi_ibft module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444865" id="444865">oops in cifs module while trying to stop a thread (kthread_stop) during filesystem mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444961" id="444961">softlockup when repeatedly dropping caches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445095" id="445095">BusLogic module can't compile in the rhel 5.2 beta kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445211" id="445211">[RFE] DTR/DSR flow control</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445422" id="445422">Feature: allow panic on softlockup warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445522" id="445522">clean up CIFS build warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445649" id="445649">[PATCH][RHEL5.1] Performance Improvement of fdatasync(2) in case of Overwrite</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445674" id="445674">Direct I/O cache invalidation after sync writes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445787" id="445787">debugfs: file/directory creation error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446068" id="446068">[RHEL5] k8_edac: typo in 'EDAC k8 MC0: GART TLB errorr: '</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446076" id="446076">[RHEL5 U2] iwl4965 -> compat module taints kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446142" id="446142">CIFS: slab error in kmem_cache_destroy(): cache `cifs_request': Can't free all objects</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446188" id="446188">BUG: Don't reserve crashkernel memory > 4 GB on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446250" id="446250">IPV6DOD: xfrm reverse icmp feature does not seem to work correctly.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446599" id="446599">jbd races lead to EIO for O_DIRECT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446707" id="446707">Add support for filetype option in audit subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446962" id="446962">Access to firewire devices is still allowed after the device is removed from the bus.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447400" id="447400">CIFS VFS: Send error in FindClose = -9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447586" id="447586">DM failing path due to a communication failure on a single i/o</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447742" id="447742">JBD: Fix typo that could result in filesystem corruption.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447748" id="447748">GFS2: lock_dlm is not always delivering callbacks in the right order</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448328" id="448328">ssh connection hangs when running command producing large text output after running "service iptables restart"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448762" id="448762">FEAT: Update ieee80211 component and associated drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448763" id="448763">FEAT: Add rt2x00 drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448764" id="448764">FEAT: Add rtl818x drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449668" id="449668">RHEL5.3: update ecryptfs kernelspace to 2.6.26 codebase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449787" id="449787">FEAT: RHEL5.3 update acpi-cpufreq driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449945" id="449945">Guest OS install causes host machine to crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449948" id="449948">Add gate.lds to Documentation/dontdiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450130" id="450130">dlm: fixes for mixed endian cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450132" id="450132">dlm: fixes for recovery of user lockspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450133" id="450133">dlm: keep cached master rsbs during recovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450135" id="450135">dlm: save master info after failed no-queue request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450136" id="450136">dlm: check for null in device_write [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450137" id="450137">dlm: fix basts for granted CW waiting PR/CW</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450138" id="450138">dlm: move plock code from gfs2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450184" id="450184">Ensure that 'noac' and/or 'actimeo=0' turn off attribute caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450219" id="450219">bonding driver can leave rtnl_lock unbalanced</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450276" id="450276">GFS2: cannot use fifo nodes (named pipes)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450566" id="450566">FEAT: RHEL5.3 backport fallocate syscall</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450786" id="450786">[Stratus 5.3 bug] kernel NULL pointer dereference at usbdev_read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450855" id="450855">Unbalance reference count in ndisc_recv_ns</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450921" id="450921">s2io intr_type documentation inaccurate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451007" id="451007">FEAT: RHEL 5.3 HDA ALSA driver update from mainstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451008" id="451008">Rpmbuild generates incorrect packages due to typos in the kernel-2.6.spec file.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451157" id="451157">[Stratus 5.3][2/2] ttyS1 lost interrupt and it stops transmitting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451196" id="451196">ip tunnel can't be bound to another device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451317" id="451317">deadlock when rpc_malloc tries to flush NFS pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451586" id="451586">RHEL5.3: SB600/700 SATA controller PMP support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451591" id="451591">Handle invalid ACPI SLIT table</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451593" id="451593">Multiple outstanding ptc.g instruction support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451745" id="451745">a check for a buggy HP SAL caused problems booting as a guest in a virtual machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451945" id="451945">Update 3w-xxxx to version 1.26.03.000-2.6.18RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451946" id="451946">Update 3w-9xxx to version 2.26.08.003-2.6.18RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452004" id="452004">gfs2: BUG: unable to handle kernel paging request at ffff81002690e000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452175" id="452175">kernel BUG at arch/i386/mm/highmem-xen.c:43! with errata/RHBA-2008-0314 installed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452535" id="452535">CONFIG_AUDITSYSCALL requires SELinux</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452577" id="452577">Actual &amp; placeholder funcs have differing param counts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452761" id="452761">r8169 driver broken in 2.6.18-92+ kernels.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453038" id="453038">Missing functions in UP kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453094" id="453094">deadlock when lockd tries to take f_sema that it already has</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453394" id="453394">[RHEL5.2]: Running strace with a bad syscall doesn't return -ENOSYS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453441" id="453441">[QLogic 5.3 bug] qla2xxx- provide additional statistics to user</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453462" id="453462">update CIFS for RHEL5.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453472" id="453472">[aacraid] aac_srb: aac_fib_send failed with status 8195</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453563" id="453563">RTL8111/8168B network card does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453574" id="453574">virtual ethernet device stops working on reception of duplicate backend state change signals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453680" id="453680">Error in the uhci code causes usb not to work with iommu=calgary boot option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453685" id="453685">[QLogic 5.3 feat] [1/n] qla2xxx- Upstream updates: 8.01.07-k7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453711" id="453711">[5.2][nfs] ls -l shows outdated timestamp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453990" id="453990">[RHEL5.3] LTP test failure in inotify02 testcase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454711" id="454711">'xm info' does not show correct info in 'node_to_cpu' field on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454792" id="454792">document divider= option in kernel docs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455060" id="455060">PTRACE_KILL does not kill the child process, rather than the child starts running freely.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455230" id="455230">v4l2 ioctl debug messages cannot be turned off</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455238" id="455238">IPsec memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455308" id="455308">Altix Partitioned System</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455424" id="455424">x86: show apicid for cpu in proc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455425" id="455425">x86: don't call MP_processor_info for disabled cpu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455427" id="455427">x86: don't call MP_processor_info for disabled cpu (64bit)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455434" id="455434">x86: fix PAE pmd_bad bootup warning</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455447" id="455447">FEAT: RHEL 5.3: (1/2) Increase deep idle state residency on idle platforms using Nehalem class processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455449" id="455449">FEAT: RHEL 5.3: (2/2) Increase deep idle state residency on idle platforms using Nehalem class processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455452" id="455452">RFE: delalloc helpers for ext4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455460" id="455460">kernel NULL pointer dereference in kobject_get_path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455471" id="455471">[NEC/Stratus 5.3 bug] various crashes in md - rdev removed in the middle of ITERATE_RDEV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455478" id="455478">2.6.26 backport of "check physical address range in ioremap" into RHEL5-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455491" id="455491">backport of fix endless page faults in mount_block_root for Linux 2.6 from 2.6.26 to RHEL5-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455504" id="455504">Backport of don't use large pages to map the first 2/4MB of memory form 2.6.26 to RHEL5-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455729" id="455729">close system call returns -ERESTARTSYS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455813" id="455813">Under heavy memory usage dma_alloc_coherent does not return aligned address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455900" id="455900">[QLogic 5.3 feat] qla2xxx - mgmt. API, CT pass thru</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456052" id="456052">kernel: fix array out of bounds when mounting with selinux options [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456169" id="456169">Need to add 3 dlm symbols to the kernel whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456215" id="456215">RHEL 5.3 HDA ALSA driver update from upstream 2008-07-22 (fixes and support for new hw)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456218" id="456218">kernel: serial open/close loop disables irq [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456300" id="456300">IPMI: Restrict keyboard io port reservation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456334" id="456334">GFS2: glock dumping misses out some glocks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456453" id="456453">GFS2: d_rwdirectempty fails with short read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456638" id="456638">[Kdump] not work on HP-XW8600</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456900" id="456900">[QLogic 5.3 feat] [0/n] qla2xxx- Netlink, FCoE management API</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457006" id="457006">ipv6: use timer pending to fix bridge reference count problem [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457013" id="457013">pppoe: Check packet length on all receive paths [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457018" id="457018">pppoe: Unshare skb before anything else [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457025" id="457025">ide-cd: fix oops when using growisofs [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457058" id="457058">ecryptfs page-sized memory allocations can corrupt memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457137" id="457137">[IA64] Fix SMP-unsafe with XENMEM_add_to_physmap on HVM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457143" id="457143">RHEL5.3: misc ecryptfs fixes from 2.6.27</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457300" id="457300">hang in ad_rx_machine due to second attempt to lock spin_lock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457569" id="457569">dlm get_comm() uses NULL pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457798" id="457798">GFS2 : gfs2meta is FUBAR</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457892" id="457892">RTL8101E performance problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457958" id="457958">Backport NetXen nic driver from upstream kernel to RHEL5.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457961" id="457961">kprobes remove causing kernel panic on ia64 with 2.6.18-92.1.10.el5 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458019" id="458019">kernel: random32: seeding improvement [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458270" id="458270">[TAHI] DAD test failure when ipv6_autoconf=yes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458289" id="458289">GFS2: rm on multiple nodes causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458360" id="458360">enable userspace kernel header check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458368" id="458368">[5.0] kdump hangs up by Sysrq+C trigger</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458441" id="458441">Make oprofile recognize Nehalem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458620" id="458620">Problem with aic79xx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458684" id="458684">GFS2: glock deadlock in page fault path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458718" id="458718">FEAT: RHEL 5.3 ext4 tech preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458749" id="458749">autofs problem with symbolic links</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458760" id="458760">kernel: dlm: dlm/user.c input validation fixes [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458774" id="458774">Kernel BUG at fs/nfs/namespace.c:103 (:nfs:nfs_follow_mountpoint)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458824" id="458824">Oprofile need to enable/disable all the counters for intel family 6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458936" id="458936">write barriers not supported, ext3 does not complain</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458988" id="458988">Panic while using pci=use_crs for resource allocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459062" id="459062">pppoe: Fix skb_unshare_check call position [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459092" id="459092">kernel dm mpath: fix several problems in dm-mapth target error paths</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459095" id="459095">kernel dm crypt: use cond_resched</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459107" id="459107">[RHEL5.3]: Hang when booting an i386 domU on an i386 HV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459221" id="459221">RHEL5.3: Patch to support new AMD HDMI Audio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459337" id="459337">dm-snap.c: Data read from snapshot may be corrupt if origin is being written to simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459436" id="459436">ext4 assembly bitops failures on s390</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459460" id="459460">kernel: cpufreq: fix format string bug [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459463" id="459463">kernel: binfmt_misc.c: avoid potential kernel stack overflow [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459527" id="459527">Performance degradation due to excessive spinlocking in the block layer when using logical volume that spans too many physical volumes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459556" id="459556">[TAHI] no echo reply for loopback address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459585" id="459585">dlm_recoverd in D state when using IPv6 to comunicate between nodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459722" id="459722">[QLogic 5.3 feat] [3/n] qla2xxx - Upstream updates: 8.02.00-k5 to 8.02.00-k6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459738" id="459738">GFS2: Multiple writer performance issue.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459786" id="459786">utrace signal handling bug interferes with systemtap uprobes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459812" id="459812">IPsec crash with MAC longer than 16 bytes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459876" id="459876">network hangs and BUG() message at boot with -105.el5debug kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460047" id="460047">Kernel obsoletes existing Driver Updates on install</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460063" id="460063">CIFS option forcedirectio fails to allow the appending of text to files.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460103" id="460103">kernel: alsa: asoc: fix double free and memory leak in many codec drivers [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460135" id="460135">CIFS: enable DFS support as tech-preview in RHEL5.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460195" id="460195">Need SCSI transport and LLD netlink support.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460593" id="460593">backport upstream kernel support for private futexes to RHEL 5.3 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460845" id="460845">Nested LVM can cause deadlock due to kcopyd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460846" id="460846">Deadlock possibility with nested LVMs with snapshots</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460857" id="460857">kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461184" id="461184">Significant regression in time() performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461414" id="461414">[QLogic 5.3 bug] qla2xxx/qla84xx: Fix 128Kb limitation in netlink messages;</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461532" id="461532">/proc/xen on bare-metal and FV guests causes multiple issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461537" id="461537">crypto: hmac(md5) self-test panics system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461671" id="461671">[RHEL5] nmi: crash during kdump kernel boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461866" id="461866">net: Enable TSO if supported by at least one device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462109" id="462109">[qlogic 5.3 bug] qla2xxx - Set rport dev loss timeout consistently</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462117" id="462117">[QLogic 5.3 bug] qla2xxx - Additional residual-count corrections during UNDERRUN handling.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462354" id="462354">dlm: add old plock interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462416" id="462416">[QLogic 5.3 bug] Update qla2xxx - PCI EE error handling support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462441" id="462441">Fix NUL handling in TTY input auditing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462500" id="462500">BUG: warning when pata_sil680 loaded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462622" id="462622">spufs in RHEL5.3: missing context switch notification log</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462663" id="462663">Netboot image for ppc too large</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462743" id="462743">libata: rmmod pata_sil680 never returns from ata_port_detach</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463206" id="463206">Regression: Tape commands are possibly retried if there is a loss of connectivity while it is running</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463277" id="463277">RHEL5.3: ext4 warning on x86 build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463416" id="463416">RHEL 5.3: fix scsi regression causing udev to hang loading sr_mod</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463470" id="463470">Regression: multipath was setting the REQ_FAILFAST flags which caused a performance drop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463478" id="463478">RHEL5.3: ecryptfs memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463500" id="463500">[RHEL5.3] Kernel-xen Oops EIP is at range_straddles_page_boundary+0x2c/0xd9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463503" id="463503">EEPROM/NVM of the e1000e becomes corrupted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464445" id="464445">xm trigger &lt;domain> init causes kernel panic.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464681" id="464681">[QLogic 5.3 bug] qla2xxx/qla84xxx: Advertise qla84xx firmware rev. fix netlink code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464868" id="464868">incorrect ATA7 handing in kernel causing ABRT errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465023" id="465023">[QLogic 5.3 bug] Update qla2xxx version to meet open source standards.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465396" id="465396">[5.3] makedumpfile: Can't get necessary symbols for excluding free pages.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465825" id="465825">panic in kcopyd during snapshot I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465856" id="465856">GFS2: recovery stuck</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466167" id="466167">RHEL5.3: posix-timers race condition causes timer to seize up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466240" id="466240">Question for LUKS device passhprase unreadable when using Xen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466246" id="466246">Interactive installation fails with ext4dev root partition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466307" id="466307">/dev/agpart missing for intel i965 HW/82G965 Graphics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466422" id="466422">RHEL5.3: Modify SATA IDE mode quirk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466774" id="466774">[RHEL5.3] kernel kernel BUG at kernel/exit.c:1129!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467153" id="467153">[QLogic 5.3 bug] latest qlogic driver takes several minutes to find LUNs on older qla2xx controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467216" id="467216">avc:  denied  { sys_resource } when using ext4dev partitions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467244" id="467244">On RHEL 5.2 32 bit rmmod bonding results in a kernel panic when configured in balance-tlb mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467689" id="467689">GFS2: Hang when shrink_slab calls gfs2_delete_inode (the GFP_NOFS bit)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467845" id="467845">RHEL 5.3: allow tcp socket buffers grow to larger than a page size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467927" id="467927">[RHEL5] patch enabling deep C states makes a RHTS machine hang on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468034" id="468034">RHEL 5.3: minor virtio_net_fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468083" id="468083">kernel-xen doesn't boot on Dell Optiplex GX280</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468148" id="468148">getsockopt() returning incorrectly in PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468187" id="468187">[autofs4] Incorrect "active offset mount" messages in syslog</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468192" id="468192">writing data to file can fail and cause panic sometimes when using xattr on ecryptfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468538" id="468538">dlm: add dlm_posix_set_fsid to kABI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468547" id="468547">RHEL5.3: Regression in ext3/jbd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468555" id="468555">[QLogic 5.3 bug] qla2xxx - restore disable by default of MSI, MSI-X</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468573" id="468573">[QLogic 5.3 bug] qla2xxx - Correct Atmel flash-part handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468870" id="468870">initscripts upgrade from 8.45.17 to 8.45.19 breaks arp_ip_target</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468873" id="468873">[QLogic 5.3 bug] qla2xxx - fails to report Option Rom version information</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468915" id="468915">[Stratus/NEC 5.3 bug] System can crash when removing input device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468922" id="468922">bnx2x + 57711 MCA on BL870c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468967" id="468967">iwlagn (Montevina &amp; Santa Rosa) fails to get associated with AP by NetworkManager frequently</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469414" id="469414">[QLogic 5.3 bug] qla3xxx, qla4xxx- Update version numbers and use new format.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469444" id="469444">[All Partners 5.3 bug] allow both ACPI code paths to use the same blacklist dmi_table correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469710" id="469710">Various firewire bugs fixed upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469711" id="469711">firewire module unload hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469715" id="469715">libata: avoid overflow in ata_tf_to_lba48() when tf->hba_lbal> 127</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469754" id="469754">kernel panic seen in ptrace_induce_signal in run of rhts test /tools/gdb/gdb-any/</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469774" id="469774">RHEL53 Beta1: network installation through cxgb3 interface failed if the adapter firmware doesn't match the cxgb3 device driver requst firmware level in rhel53.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470201" id="470201">CVE-2008-5029 kernel: Unix sockets kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470267" id="470267">cifs: data corruption due to interleaved partial writes timing out</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470449" id="470449">system-config-soundcard is not working on RHEL5.3 GA-snapshot1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470610" id="470610">[Emulex 5.3 bug] Update lpfc to version 8.2.0.33.3p</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470625" id="470625">Netdump not functioning w/ bnx2 >= v1.8h (Broadcom Netxtreme II Network Card)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471112" id="471112">gdb on ppc hangs, then panics with a kill -9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471269" id="471269">[QLogic 5.3 bug] qla2xxx - No NPIV for Loop connections.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471576" id="471576">libata: Avoid overflow in ata_tf_read_block() when tf->hba_lbal > 127</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471639" id="471639">max_phys_segments violation with dm-linear + md raid1 + cciss</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471801" id="471801">statically linked uuid segfaults in uuid_generate() on Xen kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471871" id="471871">dlm: fix up memory allocation flags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471903" id="471903">[Broadcom 5.3 bug] bnx2: add PCI-IDs for 5716s</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471933" id="471933">[Brocade/Dell 5.3 bug] hts failing memory test with EDAC i5000 Non-Fatal error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472095" id="472095">RHEL5.3 e1000e: enable ECC correction on 82571 silicon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472325" id="472325">CVE-2008-5182 kernel: fix inotify watch removal/umount races</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472382" id="472382">[QLogic 5.3 bug] qla2xx/qla84xx - Failure to establish link.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472504" id="472504">Need to build xen-platform-pci as a module and not into the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472844" id="472844">kernel panic when modprobe -r acpi_cpufreq on centrino platform with kernel newer than 2.6.18-118</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473110" id="473110">RHEL 5.3: allow tun/tap support larger MTU sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473114" id="473114">RHEL 5.3: allow virtio_net support larger MTU sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473120" id="473120">RHEL 5.3: implement virtio_net mergeable receive buffer allocate scheme</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473696" id="473696">CVE-2008-5079 Linux Kernel 'atm module' Local Denial of Service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474465" id="474465">RHEL5.3: Calgary DMA errors on IBM systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474736" id="474736">[QLogic 5.3 bug] qla4xxx - Add checks for &lt;TargetName, ISID, TargetPortGroupTag></bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474935" id="474935">fcoe: fix terminate_rport_io related problems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475652" id="475652">kdump panic introduced by hpet fix on systems without HPET</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475778" id="475778">[RHEL 5.3 Xen]: Guest hang on FV save/restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476184" id="476184">RHEL5.3 pv guests crash randomly on reboot orders.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225004" comment="kernel-headers is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225002" comment="kernel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225024" comment="kernel-doc is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225022" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225014" comment="kernel-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225010" comment="kernel-debug is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225018" comment="kernel-kdump is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225012" comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225006" comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225020" comment="kernel-PAE is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225016" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225008" comment="kernel-xen is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090256" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0256: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0256.html" />
          <reference source="CVE" ref_id="CVE-2009-0352" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0352.html" />
          <reference source="CVE" ref_id="CVE-2009-0353" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0353.html" />
          <reference source="CVE" ref_id="CVE-2009-0354" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0354.html" />
          <reference source="CVE" ref_id="CVE-2009-0355" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0355.html" />
          <reference source="CVE" ref_id="CVE-2009-0356" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0356.html" />
          <reference source="CVE" ref_id="CVE-2009-0357" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0357.html" />
          <reference source="CVE" ref_id="CVE-2009-0358" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0358.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0352, CVE-2009-0353, CVE-2009-0356)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2009-0354,
CVE-2009-0355)

A flaw was found in the way Firefox treated HTTPOnly cookies. An attacker
able to execute arbitrary JavaScript on a target site using HTTPOnly
cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357)

A flaw was found in the way Firefox treated certain HTTP page caching
directives. A local attacker could steal the contents of sensitive pages
which the page author did not intend to be cached. (CVE-2009-0358)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.6. You can find a link to the Mozilla
advisories in the References section.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.6, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-04" />
        <updated date="2009-02-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0352.html">CVE-2009-0352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0353.html">CVE-2009-0353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0354.html">CVE-2009-0354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0355.html">CVE-2009-0355</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0356.html">CVE-2009-0356</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0357.html">CVE-2009-0357</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0358.html">CVE-2009-0358</cve>
                <bugzilla href="http://bugzilla.redhat.com/456849" id="456849">missing dependency on pkgconfig in the -devel subpackage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483139" id="483139">CVE-2009-0352 Firefox layout crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483141" id="483141">CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483142" id="483142">CVE-2009-0354 Firefox XSS using a chrome XBL method and window.eval</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483143" id="483143">CVE-2009-0355 Firefox local file stealing with SessionStore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483144" id="483144">CVE-2009-0356 Firefox Chrome privilege escalation via local .desktop files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483145" id="483145">CVE-2009-0357 Firefox XMLHttpRequest allows reading HTTPOnly cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483150" id="483150">CVE-2009-0358 Firefox directives to not cache pages ignored</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256002" comment="xulrunner is earlier than 0:1.9.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256006" comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256008" comment="firefox is earlier than 0:3.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256010" comment="nss is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256011" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256014" comment="nss-tools is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256015" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256016" comment="nss-devel is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256017" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256012" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256013" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256019" comment="firefox is earlier than 0:3.0.6-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256021" comment="nss is earlier than 0:3.12.2.0-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256022" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256025" comment="nss-tools is earlier than 0:3.12.2.0-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256026" comment="nss-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256023" comment="nss-devel is earlier than 0:3.12.2.0-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256024" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090257" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0257: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0257-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0257.html" />
          <reference source="CVE" ref_id="CVE-2009-0352" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0352.html" />
          <reference source="CVE" ref_id="CVE-2009-0353" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0353.html" />
          <reference source="CVE" ref_id="CVE-2009-0355" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0355.html" />
          <reference source="CVE" ref_id="CVE-2009-0357" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0357.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-0352, CVE-2009-0353)

A flaw was found in the way malformed content was processed. A website
containing specially-crafted content could, potentially, trick a SeaMonkey
user into uploading a local file. (CVE-2009-0355)

A flaw was found in the way SeaMonkey treated HTTPOnly cookies. An attacker
able to execute arbitrary JavaScript on a target site using HTTPOnly
cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches that correct these issues. After installing the update,
SeaMonkey must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-04" />
        <updated date="2009-02-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0352.html">CVE-2009-0352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0353.html">CVE-2009-0353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0355.html">CVE-2009-0355</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0357.html">CVE-2009-0357</cve>
                <bugzilla href="http://bugzilla.redhat.com/483139" id="483139">CVE-2009-0352 Firefox layout crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483141" id="483141">CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483143" id="483143">CVE-2009-0355 Firefox local file stealing with SessionStore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483145" id="483145">CVE-2009-0357 Firefox XMLHttpRequest allows reading HTTPOnly cookies</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257018" comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257006" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257004" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257012" comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257002" comment="seamonkey is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257010" comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257020" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257016" comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257014" comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257008" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257024" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257025" comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257023" comment="seamonkey is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257028" comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257026" comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090258" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0258: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0258-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0258.html" />
          <reference source="CVE" ref_id="CVE-2009-0352" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0352.html" />
          <reference source="CVE" ref_id="CVE-2009-0353" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0353.html" />
          <reference source="CVE" ref_id="CVE-2009-0355" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0355.html" />
          <reference source="CVE" ref_id="CVE-2009-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0772.html" />
          <reference source="CVE" ref_id="CVE-2009-0774" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0774.html" />
          <reference source="CVE" ref_id="CVE-2009-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0775.html" />
          <reference source="CVE" ref_id="CVE-2009-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0776.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-0352, CVE-2009-0353, CVE-2009-0772, CVE-2009-0774,
CVE-2009-0775)

Several flaws were found in the way malformed content was processed. An
HTML mail message containing specially-crafted content could potentially
trick a Thunderbird user into surrendering sensitive information.
(CVE-2009-0355, CVE-2009-0776)

Note: JavaScript support is disabled by default in Thunderbird. None of
the above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-24" />
        <updated date="2009-03-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0352.html">CVE-2009-0352</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0353.html">CVE-2009-0353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0355.html">CVE-2009-0355</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0772.html">CVE-2009-0772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0774.html">CVE-2009-0774</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0775.html">CVE-2009-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0776.html">CVE-2009-0776</cve>
                <bugzilla href="http://bugzilla.redhat.com/483139" id="483139">CVE-2009-0352 Firefox layout crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483141" id="483141">CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483143" id="483143">CVE-2009-0355 Firefox local file stealing with SessionStore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488273" id="488273">CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488283" id="488283">CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488287" id="488287">CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488290" id="488290">CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090258002" comment="thunderbird is earlier than 0:2.0.0.21-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090258005" comment="thunderbird is earlier than 0:1.5.0.12-19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090259" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0259: mod_auth_mysql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0259-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0259.html" />
          <reference source="CVE" ref_id="CVE-2008-2384" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2384.html" />
    
    <description>The mod_auth_mysql package includes an extension module for the Apache HTTP
Server which can be used to implement web user authentication against a
MySQL database.

A flaw was found in the way mod_auth_mysql escaped certain
multibyte-encoded strings. If mod_auth_mysql was configured to use a
multibyte character set that allowed a backslash '\' as part of the
character encodings, a remote attacker could inject arbitrary SQL commands
into a login request. (CVE-2008-2384)

Note: This flaw only affected non-default installations where 
AuthMySQLCharacterSet is configured to use one of the affected multibyte
character sets. Installations that did not use the AuthMySQLCharacterSet
configuration option were not vulnerable to this flaw.

All mod_auth_mysql users are advised to upgrade to the updated package,
which contains a backported patch to resolve this issue. After installing
the update, the httpd daemon must be restarted for the fix to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-11" />
        <updated date="2009-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2384.html">CVE-2008-2384</cve>
                <bugzilla href="http://bugzilla.redhat.com/480238" id="480238">CVE-2008-2384 mod_auth_mysql: character encoding SQL injection flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090259002" comment="mod_auth_mysql is earlier than 1:3.0.0-3.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090259003" comment="mod_auth_mysql is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090261" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0261: vnc security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0261-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0261.html" />
          <reference source="CVE" ref_id="CVE-2008-4770" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4770.html" />
    
    <description>Virtual Network Computing (VNC) is a remote display system which allows you
to view a computer's "desktop" environment not only on the machine where it
is running, but from anywhere on the Internet and from a wide variety of
machine architectures.

An insufficient input validation flaw was discovered in the VNC client
application, vncviewer. If an attacker could convince a victim to connect
to a malicious VNC server, or when an attacker was able to connect to
vncviewer running in the "listen" mode, the attacker could cause the
victim's vncviewer to crash or, possibly, execute arbitrary code.
(CVE-2008-4770)

Users of vncviewer should upgrade to these updated packages, which contain
a backported patch to resolve this issue. For the update to take effect,
all running instances of vncviewer must be restarted after the update is
installed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-11" />
        <updated date="2009-02-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4770.html">CVE-2008-4770</cve>
                <bugzilla href="http://bugzilla.redhat.com/471777" id="471777">VNC Free Edition 4.1.3 fixes a  possible security vulnerability only present in the listening viewer. VNC Server is not compromised.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480590" id="480590">CVE-2008-4770 vnc: vncviewer insufficient encoding value validation in CMsgReader::readRect</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261002" comment="vnc is earlier than 0:4.1.2-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261003" comment="vnc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261004" comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261005" comment="vnc-server is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261007" comment="vnc is earlier than 0:4.0-0.beta4.1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261008" comment="vnc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261009" comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261010" comment="vnc-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261012" comment="vnc is earlier than 0:4.0-12.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261008" comment="vnc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261013" comment="vnc-server is earlier than 0:4.0-12.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261010" comment="vnc-server is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090264" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0264: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0264-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0264.html" />
          <reference source="CVE" ref_id="CVE-2008-4933" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4933.html" />
          <reference source="CVE" ref_id="CVE-2008-4934" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4934.html" />
          <reference source="CVE" ref_id="CVE-2008-5025" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5025.html" />
          <reference source="CVE" ref_id="CVE-2008-5713" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5713.html" />
          <reference source="CVE" ref_id="CVE-2009-0031" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0031.html" />
          <reference source="CVE" ref_id="CVE-2009-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0065.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* a memory leak in keyctl handling. A local user could use this flaw to
deplete kernel memory, eventually leading to a denial of service. 
(CVE-2009-0031, Important)

* a buffer overflow in the Linux kernel Partial Reliable Stream Control
Transmission Protocol (PR-SCTP) implementation. This could, potentially,
lead to a denial of service if a Forward-TSN chunk is received with a large
stream ID. (CVE-2009-0065, Important)

* a flaw when handling heavy network traffic on an SMP system with many
cores. An attacker who could send a large amount of network traffic could
create a denial of service. (CVE-2008-5713, Important)

* the code for the HFS and HFS Plus (HFS+) file systems failed to properly
handle corrupted data structures. This could, potentially, lead to a local
denial of service. (CVE-2008-4933, CVE-2008-5025, Low)

* a flaw was found in the HFS Plus (HFS+) file system implementation. This
could, potentially, lead to a local denial of service when write operations
are performed. (CVE-2008-4934, Low)

In addition, these updated packages fix the following bugs:

* when using the nfsd daemon in a clustered setup, kernel panics appeared
seemingly at random. These panics were caused by a race condition in
the device-mapper mirror target. 

* the clock_gettime(CLOCK_THREAD_CPUTIME_ID, ) syscall returned a smaller
timespec value than the result of previous clock_gettime() function
execution, which resulted in a negative, and nonsensical, elapsed time value.

* nfs_create_rpc_client was called with a "flavor" parameter which was
usually ignored and ended up unconditionally creating the RPC client with
an AUTH_UNIX flavor. This caused problems on AUTH_GSS mounts when the
credentials needed to be refreshed. The credops did not match the
authorization type, which resulted in the credops dereferencing an
incorrect part of the AUTH_UNIX rpc_auth struct.

* when copy_user_c terminated prematurely due to reading beyond the end of
the user buffer and the kernel jumped to the exception table entry, the rsi
register was not cleared. This resulted in exiting back to user code with
garbage in the rsi register.

* the hexdump data in s390dbf traces was incomplete. The length of the data
traced was incorrect and the SAN payload was read from a different place
then it was written to.

* when using connected mode (CM) in IPoIB on ehca2 hardware, it was not
possible to transmit any data.

* when an application called fork() and pthread_create() many times and, at
some point, a thread forked a child and then attempted to call the
setpgid() function, then this function failed and returned and ESRCH error
value.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Note: for this update to take effect, the
system must be rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-10" />
        <updated date="2009-02-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4933.html">CVE-2008-4933</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4934.html">CVE-2008-4934</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5025.html">CVE-2008-5025</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5713.html">CVE-2008-5713</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0031.html">CVE-2009-0031</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0065.html">CVE-2009-0065</cve>
                <bugzilla href="http://bugzilla.redhat.com/469631" id="469631">CVE-2008-4933 kernel: hfsplus: fix Buffer overflow with a corrupted image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469640" id="469640">CVE-2008-4934 kernel: hfsplus: check read_mapping_page() return value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470769" id="470769">CVE-2008-5025 kernel: hfs: fix namelength memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477744" id="477744">CVE-2008-5713 kernel: soft lockup occurs when network load is very high</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478800" id="478800">CVE-2009-0065 kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479812" id="479812">IB/ipoib: data transmission fails in connected mode on any HCA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480576" id="480576">RHEL5.2/3 - setpgid() returns ESRCH in some situations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480592" id="480592">CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480996" id="480996">zfcp: fix hexdump data in s390dbf traces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481117" id="481117">RHSA-2008:0508 linux-2.6.9-x86_64-copy_user-zero-tail.patch broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481119" id="481119">Kernel panic in auth_rpcgss:__gss_find_upcall</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481120" id="481120">oops in mirror_map (dm-raid1.c)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481122" id="481122">[5.3] clock_gettime() syscall returns a smaller timespec value than previous.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264004" comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264002" comment="kernel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264024" comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264022" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264012" comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264010" comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264018" comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264006" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264014" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264020" comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264016" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264008" comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090267" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0267: sudo security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0267.html" />
          <reference source="CVE" ref_id="CVE-2009-0034" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0034.html" />
    
    <description>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A flaw was discovered in a way sudo handled group specifications in "run
as" lists in the sudoers configuration file. If sudo configuration allowed
a user to run commands as any user of some group and the user was also a
member of that group, sudo incorrectly allowed them to run defined commands
with the privileges of any system user. This gave the user unintended
privileges. (CVE-2009-0034)

Users of sudo should update to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-05" />
        <updated date="2009-02-05" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0034.html">CVE-2009-0034</cve>
                <bugzilla href="http://bugzilla.redhat.com/481720" id="481720">CVE-2009-0034 sudo: incorrect handling of groups in Runas_User</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090267002" comment="sudo is earlier than 0:1.6.9p17-3.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090267003" comment="sudo is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090269" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0269: gstreamer-plugins security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0269-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0269.html" />
          <reference source="CVE" ref_id="CVE-2009-0398" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0398.html" />
    
    <description>The gstreamer-plugins package contains plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media types.

An array indexing error was found in the GStreamer's QuickTime media file
format decoding plug-in. An attacker could create a carefully-crafted
QuickTime media .mov file that would cause an application using GStreamer
to crash or, potentially, execute arbitrary code if played by a victim.
(CVE-2009-0398)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, all applications using GStreamer (such as
nautilus-media) must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-06" />
        <updated date="2009-02-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0398.html">CVE-2009-0398</cve>
                <bugzilla href="http://bugzilla.redhat.com/483740" id="483740">CVE-2009-0398 gstreamer-plugins: Array index error while parsing malformed QuickTime media files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090269004" comment="gstreamer-plugins-devel is earlier than 0:0.6.0-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269005" comment="gstreamer-plugins-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090269002" comment="gstreamer-plugins is earlier than 0:0.6.0-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269003" comment="gstreamer-plugins is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090270" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0270: gstreamer-plugins security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0270-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0270.html" />
          <reference source="CVE" ref_id="CVE-2009-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0397.html" />
    
    <description>The gstreamer-plugins package contains plugins used by the GStreamer
streaming-media framework to support a wide variety of media types.

A heap buffer overflow was found in the GStreamer's QuickTime media file
format decoding plug-in. An attacker could create a carefully-crafted
QuickTime media .mov file that would cause an application using GStreamer
to crash or, potentially, execute arbitrary code if played by a victim.
(CVE-2009-0397)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, all applications using GStreamer (such as rhythmbox)
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-06" />
        <updated date="2009-02-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0397.html">CVE-2009-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/481267" id="481267">CVE-2009-0397 gstreamer-plugins, gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Time-to-sample (stss) atom data</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090270004" comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269005" comment="gstreamer-plugins-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090270002" comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269003" comment="gstreamer-plugins is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090271" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:0271: gstreamer-plugins-good security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0271-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0271.html" />
          <reference source="CVE" ref_id="CVE-2009-0386" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0386.html" />
          <reference source="CVE" ref_id="CVE-2009-0387" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0387.html" />
          <reference source="CVE" ref_id="CVE-2009-0397" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0397.html" />
    
    <description>GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, GStreamer plug-ins of good quality released under the LGPL
license.

Multiple heap buffer overflows and an array indexing error were found in
the GStreamer's QuickTime media file format decoding plugin. An attacker
could create a carefully-crafted QuickTime media .mov file that would cause
an application using GStreamer to crash or, potentially, execute arbitrary
code if played by a victim. (CVE-2009-0386, CVE-2009-0387, CVE-2009-0397)

All users of gstreamer-plugins-good are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as totem or
rhythmbox) must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-06" />
        <updated date="2009-02-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0386.html">CVE-2009-0386</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0387.html">CVE-2009-0387</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0397.html">CVE-2009-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/481267" id="481267">CVE-2009-0397 gstreamer-plugins, gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Time-to-sample (stss) atom data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483736" id="483736">CVE-2009-0386 gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Composition Time To Sample (aka ctts) atom data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483737" id="483737">CVE-2009-0387 gstreamer-plugins-good: Array index error while parsing malformed QuickTime media files via crafted Sync Sample (aka stss) atom data</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090271004" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090271005" comment="gstreamer-plugins-good-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090271002" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090271003" comment="gstreamer-plugins-good is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090275" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0275: imap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0275-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0275.html" />
          <reference source="CVE" ref_id="CVE-2008-5005" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5005.html" />
    
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access protocols.

A buffer overflow flaw was discovered in the dmail and tmail mail delivery
utilities shipped with imap. If either of these utilities were used as a
mail delivery agent, a remote attacker could potentially use this flaw to
run arbitrary code as the targeted user by sending a specially-crafted mail
message to the victim. (CVE-2008-5005)

Users of imap should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-19" />
        <updated date="2009-02-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5005.html">CVE-2008-5005</cve>
                <bugzilla href="http://bugzilla.redhat.com/469667" id="469667">CVE-2008-5005 uw-imap: buffer overflow in dmail and tmail</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090275006" comment="imap-utils is earlier than 1:2002d-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090275007" comment="imap-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090275004" comment="imap-devel is earlier than 1:2002d-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090275005" comment="imap-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090275002" comment="imap is earlier than 1:2002d-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090275003" comment="imap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090295" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0295: net-snmp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0295-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0295.html" />
          <reference source="CVE" ref_id="CVE-2008-6123" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6123.html" />
    
    <description>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

It was discovered that the snmpd daemon did not use TCP wrappers correctly,
causing network hosts access restrictions defined in "/etc/hosts.allow" and
"/etc/hosts.deny" to not be honored. A remote attacker could use this flaw
to bypass intended access restrictions. (CVE-2008-6123)

This issue only affected configurations where hosts.allow and hosts.deny
were used to limit access to the SNMP server. To obtain information from
the server, the attacker would have to successfully authenticate, usually
by providing a correct community string.

All net-snmp users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the update, the
snmpd and snmptrapd daemons will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-26" />
        <updated date="2009-03-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6123.html">CVE-2008-6123</cve>
                <bugzilla href="http://bugzilla.redhat.com/485211" id="485211">CVE-2008-6123 net-snmp: incorrect application of hosts access restrictions in hosts.{allow,deny}</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295006" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295007" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295008" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295009" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295010" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295011" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295004" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295002" comment="net-snmp is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090296" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0296: icu security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0296-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0296.html" />
          <reference source="CVE" ref_id="CVE-2008-1036" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1036.html" />
    
    <description>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

A flaw was found in the way ICU processed certain, invalid, encoded data.
If an application used ICU to decode malformed, multibyte, character data,
it may have been possible to bypass certain content protection mechanisms,
or display information in a manner misleading to the user. (CVE-2008-1036)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-12" />
        <updated date="2009-03-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1036.html">CVE-2008-1036</cve>
                <bugzilla href="http://bugzilla.redhat.com/464168" id="464168">CVE-2008-1036 ICU: Invalid character sequences omission during conversion of some character encodings (XSS attack possible)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296006" comment="libicu is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296007" comment="libicu is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296008" comment="libicu-devel is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296009" comment="libicu-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296004" comment="libicu-doc is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296005" comment="libicu-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296002" comment="icu is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296003" comment="icu is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090308" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0308: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0308-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0308.html" />
          <reference source="CVE" ref_id="CVE-2009-0577" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0577.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

The CUPS security advisory, RHSA-2008:0937, stated that it fixed
CVE-2008-3640 for Red Hat Enterprise Linux 3, 4, and 5. It was discovered
this flaw was not properly fixed on Red Hat Enterprise Linux 3, however.
(CVE-2009-0577)

These new packages contain a proper fix for CVE-2008-3640 on Red Hat
Enterprise Linux 3. Red Hat Enterprise Linux 4 and 5 already contain the
appropriate fix for this flaw and do not need to be updated.

Users of cups should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-19" />
        <updated date="2009-02-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0577.html">CVE-2009-0577</cve>
                <bugzilla href="http://bugzilla.redhat.com/486052" id="486052">CVE-2009-0577 cups-CVE-2008-3640.patch has been corrupted.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090308006" comment="cups-devel is earlier than 1:1.1.17-13.3.56" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090308004" comment="cups-libs is earlier than 1:1.1.17-13.3.56" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090308002" comment="cups is earlier than 1:1.1.17-13.3.56" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090313" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0313: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0313-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0313.html" />
          <reference source="CVE" ref_id="CVE-2008-4680" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4680.html" />
          <reference source="CVE" ref_id="CVE-2008-4681" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4681.html" />
          <reference source="CVE" ref_id="CVE-2008-4682" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4682.html" />
          <reference source="CVE" ref_id="CVE-2008-4683" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4683.html" />
          <reference source="CVE" ref_id="CVE-2008-4684" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4684.html" />
          <reference source="CVE" ref_id="CVE-2008-4685" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4685.html" />
          <reference source="CVE" ref_id="CVE-2008-5285" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5285.html" />
          <reference source="CVE" ref_id="CVE-2008-6472" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6472.html" />
          <reference source="CVE" ref_id="CVE-2009-0599" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0599.html" />
          <reference source="CVE" ref_id="CVE-2009-0600" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0600.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network or opened a malformed dump file, it could
crash or, possibly, execute arbitrary code as the user running Wireshark.
(CVE-2008-4683, CVE-2009-0599)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malformed dump file. (CVE-2008-4680, CVE-2008-4681, CVE-2008-4682,
CVE-2008-4684, CVE-2008-4685, CVE-2008-5285, CVE-2009-0600)

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.6, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4680.html">CVE-2008-4680</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4681.html">CVE-2008-4681</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4682.html">CVE-2008-4682</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4683.html">CVE-2008-4683</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4684.html">CVE-2008-4684</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4685.html">CVE-2008-4685</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5285.html">CVE-2008-5285</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6472.html">CVE-2008-6472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0599.html">CVE-2009-0599</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0600.html">CVE-2009-0600</cve>
                <bugzilla href="http://bugzilla.redhat.com/468166" id="468166">CVE-2008-4680 wireshark: DoS (app crash or abort) via malformed USB Request Block (URB).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468167" id="468167">CVE-2008-4681 wireshark: DoS (app crash or abort) in Bluetooth RFCOMM dissector via unknown packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468169" id="468169">CVE-2008-4682 wireshark: DoS (app abort) via a malformed  .ncf file with an unknown/unexpected packet type</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468171" id="468171">CVE-2008-4683 wireshark: DoS (app crash or abort) in Bluetooth ACL dissector  via a packet with an invalid length</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468174" id="468174">CVE-2008-4684 wireshark: DoS (app crash) via certain series of packets by enabling the (1) PRP or (2) MATE post dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468175" id="468175">CVE-2008-4685 wireshark: DoS (app crash or abort) in Q.931 dissector via certain packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472737" id="472737">CVE-2008-5285 wireshark: DoS (infinite loop) in SMTP dissector via large SMTP request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485888" id="485888">CVE-2009-0599 wireshark: buffer overflows in NetScreen snoop file reader</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485889" id="485889">CVE-2009-0600 wireshark: denial of service (application crash) via a crafted Tektronix K12 text capture file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313002" comment="wireshark is earlier than 0:1.0.6-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313004" comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313007" comment="wireshark is earlier than 0:1.0.6-EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313009" comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313012" comment="wireshark is earlier than 0:1.0.6-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313013" comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090315" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0315: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0315-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0315.html" />
          <reference source="CVE" ref_id="CVE-2009-0040" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0040.html" />
          <reference source="CVE" ref_id="CVE-2009-0771" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0771.html" />
          <reference source="CVE" ref_id="CVE-2009-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0772.html" />
          <reference source="CVE" ref_id="CVE-2009-0773" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0773.html" />
          <reference source="CVE" ref_id="CVE-2009-0774" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0774.html" />
          <reference source="CVE" ref_id="CVE-2009-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0775.html" />
          <reference source="CVE" ref_id="CVE-2009-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0776.html" />
          <reference source="CVE" ref_id="CVE-2009-0777" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0777.html" />
    
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0040, CVE-2009-0771, CVE-2009-0772, CVE-2009-0773, CVE-2009-0774,
CVE-2009-0775)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2009-0776,
CVE-2009-0777)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.7. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.7, and which correct these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0040.html">CVE-2009-0040</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0771.html">CVE-2009-0771</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0772.html">CVE-2009-0772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0773.html">CVE-2009-0773</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0774.html">CVE-2009-0774</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0775.html">CVE-2009-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0776.html">CVE-2009-0776</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0777.html">CVE-2009-0777</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488272" id="488272">CVE-2009-0771 Firefox 3 Layout Engine Crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488273" id="488273">CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488276" id="488276">CVE-2009-0773 Firefox 3 crashes in the JavaScript engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488283" id="488283">CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488287" id="488287">CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488290" id="488290">CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488292" id="488292">CVE-2009-0777 Firefox URL spoofing with invisible control characters</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315002" comment="firefox is earlier than 0:3.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315008" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315004" comment="xulrunner is earlier than 0:1.9.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315006" comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090315011" comment="firefox is earlier than 0:3.0.7-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090325" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0325: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0325-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0325.html" />
          <reference source="CVE" ref_id="CVE-2009-0040" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0040.html" />
          <reference source="CVE" ref_id="CVE-2009-0772" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0772.html" />
          <reference source="CVE" ref_id="CVE-2009-0774" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0774.html" />
          <reference source="CVE" ref_id="CVE-2009-0775" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0775.html" />
          <reference source="CVE" ref_id="CVE-2009-0776" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0776.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-0040, CVE-2009-0772, CVE-2009-0774, CVE-2009-0775)

A flaw was found in the way malformed content was processed. A website
containing specially-crafted content could, potentially, trick a SeaMonkey
user into surrendering sensitive information. (CVE-2009-0776)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches that correct these issues. After installing the update,
SeaMonkey must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0040.html">CVE-2009-0040</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0772.html">CVE-2009-0772</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0774.html">CVE-2009-0774</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0775.html">CVE-2009-0775</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0776.html">CVE-2009-0776</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488273" id="488273">CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488283" id="488283">CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488287" id="488287">CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488290" id="488290">CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325004" comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325018" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325016" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325020" comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325002" comment="seamonkey is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325006" comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325012" comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325008" comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325014" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325024" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325028" comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325023" comment="seamonkey is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325026" comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325025" comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090326" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0326: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0326-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0326.html" />
          <reference source="CVE" ref_id="CVE-2008-3528" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3528.html" />
          <reference source="CVE" ref_id="CVE-2008-5700" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5700.html" />
          <reference source="CVE" ref_id="CVE-2009-0028" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0028.html" />
          <reference source="CVE" ref_id="CVE-2009-0269" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0269.html" />
          <reference source="CVE" ref_id="CVE-2009-0322" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0322.html" />
          <reference source="CVE" ref_id="CVE-2009-0675" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0675.html" />
          <reference source="CVE" ref_id="CVE-2009-0676" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0676.html" />
          <reference source="CVE" ref_id="CVE-2009-0778" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0778.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* memory leaks were found on some error paths in the icmp_send()
function in the Linux kernel. This could, potentially, cause the network
connectivity to cease. (CVE-2009-0778, Important)

* Chris Evans reported a deficiency in the clone() system call when called
with the CLONE_PARENT flag. This flaw permits the caller (the parent
process) to indicate an arbitrary signal it wants to receive when its child
process exits. This could lead to a denial of service of the parent
process. (CVE-2009-0028, Moderate)

* an off-by-one underflow flaw was found in the eCryptfs subsystem. This
could potentially cause a local denial of service when the readlink()
function returned an error. (CVE-2009-0269, Moderate)

* a deficiency was found in the Remote BIOS Update (RBU) driver for Dell
systems. This could allow a local, unprivileged user to cause a denial of
service by reading zero bytes from the image_type or packet_size files in
"/sys/devices/platform/dell_rbu/". (CVE-2009-0322, Moderate)

* an inverted logic flaw was found in the SysKonnect FDDI PCI adapter
driver, allowing driver statistics to be reset only when the CAP_NET_ADMIN
capability was absent (local, unprivileged users could reset driver
statistics). (CVE-2009-0675, Moderate)

* the sock_getsockopt() function in the Linux kernel did not properly
initialize a data structure that can be directly returned to user-space
when the getsockopt() function is called with SO_BSDCOMPAT optname set.
This flaw could possibly lead to memory disclosure.
(CVE-2009-0676, Moderate)

* the ext2 and ext3 file system code failed to properly handle corrupted
data structures, leading to a possible local denial of service when read
or write operations were performed on a specially-crafted file system.
(CVE-2008-3528, Low)

* a deficiency was found in the libATA implementation. This could,
potentially, lead to a local denial of service. Note: by default, the
"/dev/sg*" devices are accessible only to the root user.
(CVE-2008-5700, Low)

Bug fixes:

* a bug in aic94xx may have caused kernel panics during boot on some
systems with certain SATA disks. (BZ#485909)

* a word endianness problem in the qla2xx driver on PowerPC-based machines
may have corrupted flash-based devices. (BZ#485908)

* a memory leak in pipe() may have caused a system deadlock. The workaround
in Section 1.5, Known Issues, of the Red Hat Enterprise Linux 5.3 Release
Notes Updates, which involved manually allocating extra file descriptors to
processes calling do_pipe, is no longer necessary. (BZ#481576)

* CPU soft-lockups in the network rate estimator. (BZ#481746)

* bugs in the ixgbe driver caused it to function unreliably on some
systems with 16 or more CPU cores. (BZ#483210)

* the iwl4965 driver may have caused a kernel panic. (BZ#483206)

* a bug caused NFS attributes to not update for some long-lived NFS
mounted file systems. (BZ#483201)

* unmounting a GFS2 file system may have caused a panic. (BZ#485910)

* a bug in ptrace() may have caused a panic when single stepping a target.
(BZ#487394)

* on some 64-bit systems, notsc was incorrectly set at boot, causing slow
gettimeofday() calls. (BZ#488239)

* do_machine_check() cleared all Machine Check Exception (MCE) status
registers, preventing the BIOS from using them to determine the cause of
certain panics and errors. (BZ#490433)

* scaling problems caused performance problems for LAPI applications.
(BZ#489457)

* a panic may have occurred on systems using certain Intel WiFi Link 5000
products when booting with the RF Kill switch on. (BZ#489846)

* the TSC is invariant with C/P/T states, and always runs at constant
frequency from now on. (BZ#489310)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues. The system must be rebooted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-01" />
        <updated date="2009-04-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3528.html">CVE-2008-3528</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5700.html">CVE-2008-5700</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0028.html">CVE-2009-0028</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0269.html">CVE-2009-0269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0322.html">CVE-2009-0322</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0675.html">CVE-2009-0675</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0676.html">CVE-2009-0676</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0778.html">CVE-2009-0778</cve>
                <bugzilla href="http://bugzilla.redhat.com/459577" id="459577">CVE-2008-3528 Linux kernel ext[234] directory corruption denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474495" id="474495">CVE-2008-5700 kernel: enforce a minimum SG_IO timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479932" id="479932">CVE-2009-0028 Linux kernel minor signal handling vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481576" id="481576">multipath test causes memory leak and eventual system deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481604" id="481604">CVE-2009-0269 kernel: ecryptfs readlink flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481746" id="481746">[RHEL 5] gen_estimator deadlock fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482866" id="482866">CVE-2009-0322 kernel: dell_rbu local oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483201" id="483201">NFS problem#3 of IT 106473 - 32-bit jiffy wrap around - NFS inode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483206" id="483206">Kernel panic in iwl4965 driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485163" id="485163">CVE-2009-0778 kernel: rt_cache leak leads to lack of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485908" id="485908">[QLogic 5.4 bug] qla2xx - Word-endian problem programming flash on PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485909" id="485909">Panic at boot if SATA disk is present</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485910" id="485910">reproducible panic in debugfs_remove when unmounting gfs2 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486305" id="486305">CVE-2009-0676 kernel: memory disclosure in SO_BSDCOMPAT gsopt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486534" id="486534">CVE-2009-0675 kernel: skfp_ioctl inverted logic flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487394" id="487394">kernel BUG at kernel/ptrace.c:1068</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488239" id="488239">RHEL5 kernel forces notsc on certain systems [C-state support dependant]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489310" id="489310">[Intel 5.4 FEAT] TSC keeps running in C3+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489457" id="489457">Lapi takes too long to run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489846" id="489846">RHEL 5.3 GA kernel panics when RF Kill is on in 5100/5300 AGN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490433" id="490433">RHEL5.3 (x86_64): MCE handler must not clear status registers on fatal conditions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326004" comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326002" comment="kernel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326024" comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326022" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326012" comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326008" comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326016" comment="kernel-kdump is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326010" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326006" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326020" comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326018" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326014" comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090329" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:0329: freetype security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0329-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0329.html" />
          <reference source="CVE" ref_id="CVE-2006-1861" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-1861.html" />
          <reference source="CVE" ref_id="CVE-2007-2754" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2754.html" />
          <reference source="CVE" ref_id="CVE-2008-1808" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1808.html" />
          <reference source="CVE" ref_id="CVE-2009-0946" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0946.html" />
    
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide both the FreeType 1 and FreeType 2
font engines.

Tavis Ormandy of the Google Security Team discovered several integer
overflow flaws in the FreeType 2 font engine. If a user loaded a
carefully-crafted font file with an application linked against FreeType 2,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2009-0946)

Chris Evans discovered multiple integer overflow flaws in the FreeType font
engine. If a user loaded a carefully-crafted font file with an application
linked against FreeType, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2006-1861)

An integer overflow flaw was found in the way the FreeType font engine
processed TrueType® Font (TTF) files. If a user loaded a carefully-crafted
font file with an application linked against FreeType, it could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2007-2754)

A flaw was discovered in the FreeType TTF font-file format parser when the
TrueType virtual machine Byte Code Interpreter (BCI) is enabled. If a user
loaded a carefully-crafted font file with an application linked against
FreeType, it could cause the application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2008-1808)

The CVE-2008-1808 flaw did not affect the freetype packages as distributed
in Red Hat Enterprise Linux 3 and 4, as they are not compiled with TrueType
BCI support. A fix for this flaw has been included in this update as users
may choose to recompile the freetype packages in order to enable TrueType
BCI support. Red Hat does not, however, provide support for modified and
recompiled packages.

Note: For the FreeType 2 font engine, the CVE-2006-1861, CVE-2007-2754,
and CVE-2008-1808 flaws were addressed via RHSA-2006:0500, RHSA-2007:0403,
and RHSA-2008:0556 respectively. This update provides corresponding
updates for the FreeType 1 font engine, included in the freetype packages
distributed in Red Hat Enterprise Linux 3 and 4.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-1861.html">CVE-2006-1861</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2754.html">CVE-2007-2754</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1808.html">CVE-2008-1808</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0946.html">CVE-2009-0946</cve>
                <bugzilla href="http://bugzilla.redhat.com/240200" id="240200">CVE-2007-2754 freetype integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450774" id="450774">CVE-2008-1808 FreeType off-by-one flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484437" id="484437">CVE-2006-1861 freetype: multiple integer overflow vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491384" id="491384">CVE-2009-0946 freetype: multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329008" comment="freetype-utils is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329009" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329002" comment="freetype is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329003" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329004" comment="freetype-demos is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329005" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329006" comment="freetype-devel is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329007" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329013" comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329009" comment="freetype-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329011" comment="freetype is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329003" comment="freetype is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329012" comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329005" comment="freetype-demos is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329014" comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329007" comment="freetype-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090331" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0331: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0331-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0331.html" />
          <reference source="CVE" ref_id="CVE-2008-5700" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5700.html" />
          <reference source="CVE" ref_id="CVE-2009-0031" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0031.html" />
          <reference source="CVE" ref_id="CVE-2009-0065" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0065.html" />
          <reference source="CVE" ref_id="CVE-2009-0322" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0322.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* a buffer overflow was found in the Linux kernel Partial Reliable Stream
Control Transmission Protocol (PR-SCTP) implementation. This could,
potentially, lead to a denial of service if a Forward-TSN chunk is received
with a large stream ID. (CVE-2009-0065, Important)

* a memory leak was found in keyctl handling. A local, unprivileged user
could use this flaw to deplete kernel memory, eventually leading to a
denial of service. (CVE-2009-0031, Important)

* a deficiency was found in the Remote BIOS Update (RBU) driver for Dell
systems. This could allow a local, unprivileged user to cause a denial of
service by reading zero bytes from the image_type or packet_size file in
"/sys/devices/platform/dell_rbu/". (CVE-2009-0322, Important)

* a deficiency was found in the libATA implementation. This could,
potentially, lead to a denial of service. Note: by default, "/dev/sg*"
devices are accessible only to the root user. (CVE-2008-5700, Low)

This update also fixes the following bugs:

* when the hypervisor changed a page table entry (pte) mapping from
read-only to writable via a make_writable hypercall, accessing the changed
page immediately following the change caused a spurious page fault. When
trying to install a para-virtualized Red Hat Enterprise Linux 4 guest on a
Red Hat Enterprise Linux 5.3 dom0 host, this fault crashed the installer
with a kernel backtrace. With this update, the "spurious" page fault is
handled properly. (BZ#483748)

* net_rx_action could detect its cpu poll_list as non-empty, but have that
same list reduced to empty by the poll_napi path. This resulted in garbage
data being returned when net_rx_action calls list_entry, which subsequently
resulted in several possible crash conditions. The race condition in the
network code which caused this has been fixed. (BZ#475970, BZ#479681,
BZ#480741)

* a misplaced memory barrier at unlock_buffer() could lead to a concurrent
h_refcounter update which produced a reference counter leak and, later, a
double free in ext3_xattr_release_block(). Consequent to the double free,
ext3 reported an error

    ext3_free_blocks_sb: bit already cleared for block [block number]

and mounted itself as read-only. With this update, the memory barrier is
now placed before the buffer head lock bit, forcing the write order and
preventing the double free. (BZ#476533)

* when the iptables module was unloaded, it was assumed the correct entry
for removal had been found if "wrapper->ops->pf" matched the value passed
in by "reg->pf". If several ops ranges were registered against the same
protocol family, however, (which was likely if you had both ip_conntrack
and ip_contrack_* loaded) this assumption could lead to NULL list pointers
and cause a kernel panic. With this update, "wrapper->ops" is matched to
pointer values "reg", which ensures the correct entry is removed and
results in no NULL list pointers. (BZ#477147)

* when the pidmap page (used for tracking process ids, pids) incremented to
an even page (ie the second, fourth, sixth, etc. pidmap page), the
alloc_pidmap() routine skipped the page. This resulted in "holes" in the
allocated pids. For example, after pid 32767, you would expect 32768 to be
allocated. If the page skipping behavior presented, however, the pid
allocated after 32767 was 65536. With this update, alloc_pidmap() no longer
skips alternate pidmap pages and allocated pid holes no longer occur. This
fix also corrects an error which allowed pid_max to be set higher than the
pid_max limit has been corrected. (BZ#479182)

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues. The
system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-12" />
        <updated date="2009-03-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5700.html">CVE-2008-5700</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0031.html">CVE-2009-0031</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0065.html">CVE-2009-0065</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0322.html">CVE-2009-0322</cve>
                <bugzilla href="http://bugzilla.redhat.com/474495" id="474495">CVE-2008-5700 kernel: enforce a minimum SG_IO timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475970" id="475970">oops in e1000_clean (list corruption due to race with e1000_down)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476533" id="476533">Read-only filesystem after 'ext3_free_blocks_sb: bit already cleared for block' errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477147" id="477147">Kernel panic when unloading ip conntrack modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478800" id="478800">CVE-2009-0065 kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479182" id="479182">RHEL4 64 bit skips all pids with bit 15 set (32768-65535, 98304-131071 etc)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479681" id="479681">oops in net_rx_action on double free of dev->poll_list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480592" id="480592">CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480741" id="480741">RHEL4.8 kernel crashed in net_rx_action() on IA64 machine in RHTS connectathon test</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482866" id="482866">CVE-2009-0322 kernel: dell_rbu local oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483748" id="483748">rhel4 PV guest installations busted on rhel 5.3 i386 intel dom0</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331002" comment="kernel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331022" comment="kernel-doc is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331004" comment="kernel-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331006" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331020" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331010" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331016" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331014" comment="kernel-xenU is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331012" comment="kernel-smp is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090332" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0332: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0332-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0332.html" />
          <reference source="CVE" ref_id="CVE-2009-0519" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0519.html" />
          <reference source="CVE" ref_id="CVE-2009-0520" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0520.html" />
          <reference source="CVE" ref_id="CVE-2009-0521" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0521.html" />
    
    <description>The flash-plugin package contains a Firefox-compatible Adobe Flash Player
Web browser plug-in.

Multiple input validation flaws were found in the way Flash Player
displayed certain SWF (Shockwave Flash) content. An attacker could use
these flaws to create a specially-crafted SWF file that could cause
flash-plugin to crash, or, possibly, execute arbitrary code when the victim
loaded a page containing the specially-crafted SWF content. (CVE-2009-0520,
CVE-2009-0519)

It was discovered that Adobe Flash Player had an insecure RPATH (runtime
library search path) set in the ELF (Executable and Linking Format) header.
A local user with write access to the directory pointed to by RPATH could
use this flaw to execute arbitrary code with the privileges of the user
running Adobe Flash Player. (CVE-2009-0521)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.0.22.87.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-25" />
        <updated date="2009-02-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0519.html">CVE-2009-0519</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0520.html">CVE-2009-0520</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0521.html">CVE-2009-0521</cve>
                <bugzilla href="http://bugzilla.redhat.com/487141" id="487141">CVE-2009-0519 flash-plugin: Input validation flaw (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487142" id="487142">CVE-2009-0520 flash-plugin: Buffer overflow (arbitrary code execution) via crafted SWF file.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487144" id="487144">CVE-2009-0521 flash-plugin: Linux-specific information disclosure (privilege escalation)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090332002" comment="flash-plugin is earlier than 0:10.0.22.87-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090332003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090333" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0333: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0333-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0333.html" />
          <reference source="CVE" ref_id="CVE-2008-1382" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1382.html" />
          <reference source="CVE" ref_id="CVE-2009-0040" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0040.html" />
    
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was discovered in libpng that could result in libpng trying to
free() random memory if certain, unlikely error conditions occurred. If a
carefully-crafted PNG file was loaded by an application linked against
libpng, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-0040)

A flaw was discovered in the way libpng handled PNG images containing
"unknown" chunks. If an application linked against libpng attempted to
process a malformed, unknown chunk in a malicious PNG image, it could cause
the application to crash. (CVE-2008-1382)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1382.html">CVE-2008-1382</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0040.html">CVE-2009-0040</cve>
                <bugzilla href="http://bugzilla.redhat.com/441839" id="441839">CVE-2008-1382 libpng unknown chunk handling flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333002" comment="libpng is earlier than 2:1.2.10-7.1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333003" comment="libpng is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333004" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333005" comment="libpng-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333007" comment="libpng is earlier than 2:1.2.7-3.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333008" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333009" comment="libpng-devel is earlier than 2:1.2.7-3.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333010" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333013" comment="libpng10-devel is earlier than 0:1.0.16-3.el4_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333014" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333011" comment="libpng10 is earlier than 0:1.0.16-3.el4_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333012" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090336" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0336: glib2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0336.html" />
          <reference source="CVE" ref_id="CVE-2008-4316" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4316.html" />
    
    <description>GLib is the low-level core library that forms the basis for projects such
as GTK+ and GNOME. It provides data structure handling for C, portability
wrappers, and interfaces for such runtime functionality as an event loop,
threads, dynamic loading, and an object system.

Diego Pettenò discovered multiple integer overflows causing heap-based
buffer overflows in GLib's Base64 encoding and decoding functions. An
attacker could use these flaws to crash an application using GLib's Base64
functions to encode or decode large, untrusted inputs, or, possibly,
execute arbitrary code as the user running the application. (CVE-2008-4316)

Note: No application shipped with Red Hat Enterprise Linux 5 uses the
affected functions. Third-party applications may, however, be affected.

All users of glib2 should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-24" />
        <updated date="2009-03-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4316.html">CVE-2008-4316</cve>
                <bugzilla href="http://bugzilla.redhat.com/474770" id="474770">CVE-2008-4316 glib2: integer overflows in the base64 handling functions (oCERT-2008-015)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090336004" comment="glib2-devel is earlier than 0:2.12.3-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090336005" comment="glib2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090336002" comment="glib2 is earlier than 0:2.12.3-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090336003" comment="glib2 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090337" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0337: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0337.html" />
          <reference source="CVE" ref_id="CVE-2008-3658" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3658.html" />
          <reference source="CVE" ref_id="CVE-2008-3660" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3660.html" />
          <reference source="CVE" ref_id="CVE-2008-5498" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5498.html" />
          <reference source="CVE" ref_id="CVE-2008-5557" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5557.html" />
          <reference source="CVE" ref_id="CVE-2009-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0754.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A heap-based buffer overflow flaw was found in PHP's mbstring extension. A
remote attacker able to pass arbitrary input to a PHP script using mbstring
conversion functions could cause the PHP interpreter to crash or,
possibly, execute arbitrary code. (CVE-2008-5557)

A flaw was found in the handling of the "mbstring.func_overload"
configuration setting. A value set for one virtual host, or in a user's
.htaccess file, was incorrectly applied to other virtual hosts on the same
server, causing the handling of multibyte character strings to not work
correctly. (CVE-2009-0754)

A buffer overflow flaw was found in PHP's imageloadfont function.  If a PHP
script allowed a remote attacker to load a carefully crafted font file, it
could cause the PHP interpreter to crash or, possibly, execute arbitrary
code. (CVE-2008-3658)

A flaw was found in the way PHP handled certain file extensions when
running in FastCGI mode. If the PHP interpreter was being executed via
FastCGI, a remote attacker could create a request which would cause the PHP
interpreter to crash. (CVE-2008-3660)

A memory disclosure flaw was found in the PHP gd extension's imagerotate
function. A remote attacker able to pass arbitrary values as the
"background color" argument of the function could, possibly, view portions
of the PHP interpreter's memory. (CVE-2008-5498)

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The httpd web server
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-06" />
        <updated date="2009-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3658.html">CVE-2008-3658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3660.html">CVE-2008-3660</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5498.html">CVE-2008-5498</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5557.html">CVE-2008-5557</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0754.html">CVE-2009-0754</cve>
                <bugzilla href="http://bugzilla.redhat.com/459529" id="459529">CVE-2008-3658 php: buffer overflow in the imageloadfont function in gd extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459572" id="459572">CVE-2008-3660 php: FastCGI module DoS via multiple dots preceding the extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478425" id="478425">CVE-2008-5498 php: libgd imagerotate() array index error memory disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478848" id="478848">CVE-2008-5557 php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479272" id="479272">CVE-2009-0754 PHP mbstring.func_overload web server denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337008" comment="php-odbc is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337009" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337010" comment="php-mysql is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337002" comment="php is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337006" comment="php-pgsql is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337007" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337012" comment="php-devel is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337013" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337004" comment="php-imap is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337005" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337014" comment="php-ldap is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337015" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337030" comment="php-odbc is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337009" comment="php-odbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337019" comment="php-gd is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337020" comment="php-gd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337023" comment="php-mysql is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337011" comment="php-mysql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337017" comment="php is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337003" comment="php is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337028" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337029" comment="php-xmlrpc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337031" comment="php-mbstring is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337032" comment="php-mbstring is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337033" comment="php-pgsql is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337007" comment="php-pgsql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337024" comment="php-devel is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337013" comment="php-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337036" comment="php-ncurses is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337037" comment="php-ncurses is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337034" comment="php-snmp is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337035" comment="php-snmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337018" comment="php-imap is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337005" comment="php-imap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337026" comment="php-pear is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337027" comment="php-pear is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337025" comment="php-ldap is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337015" comment="php-ldap is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337021" comment="php-domxml is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337022" comment="php-domxml is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090338" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0338: php security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0338-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0338.html" />
          <reference source="CVE" ref_id="CVE-2008-3658" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3658.html" />
          <reference source="CVE" ref_id="CVE-2008-3660" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3660.html" />
          <reference source="CVE" ref_id="CVE-2008-5498" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5498.html" />
          <reference source="CVE" ref_id="CVE-2008-5557" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5557.html" />
          <reference source="CVE" ref_id="CVE-2008-5814" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5814.html" />
          <reference source="CVE" ref_id="CVE-2009-0754" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0754.html" />
    
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A heap-based buffer overflow flaw was found in PHP's mbstring extension. A
remote attacker able to pass arbitrary input to a PHP script using mbstring
conversion functions could cause the PHP interpreter to crash or,
possibly, execute arbitrary code. (CVE-2008-5557)

A flaw was found in the handling of the "mbstring.func_overload"
configuration setting. A value set for one virtual host, or in a user's
.htaccess file, was incorrectly applied to other virtual hosts on the same
server, causing the handling of multibyte character strings to not work
correctly. (CVE-2009-0754)

A buffer overflow flaw was found in PHP's imageloadfont function.  If a PHP
script allowed a remote attacker to load a carefully crafted font file, it
could cause the PHP interpreter to crash or, possibly, execute arbitrary
code. (CVE-2008-3658)

A flaw was found in the way PHP handled certain file extensions when
running in FastCGI mode. If the PHP interpreter was being executed via
FastCGI, a remote attacker could create a request which would cause the PHP
interpreter to crash. (CVE-2008-3660)

A memory disclosure flaw was found in the PHP gd extension's imagerotate
function. A remote attacker able to pass arbitrary values as the
"background color" argument of the function could, possibly, view portions
of the PHP interpreter's memory. (CVE-2008-5498)

A cross-site scripting flaw was found in a way PHP reported errors for
invalid cookies. If the PHP interpreter had "display_errors" enabled, a
remote attacker able to set a specially-crafted cookie on a victim's system
could possibly inject arbitrary HTML into an error message generated by
PHP. (CVE-2008-5814)

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The httpd web server
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-06" />
        <updated date="2009-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3658.html">CVE-2008-3658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3660.html">CVE-2008-3660</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5498.html">CVE-2008-5498</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5557.html">CVE-2008-5557</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5814.html">CVE-2008-5814</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0754.html">CVE-2009-0754</cve>
                <bugzilla href="http://bugzilla.redhat.com/459529" id="459529">CVE-2008-3658 php: buffer overflow in the imageloadfont function in gd extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459572" id="459572">CVE-2008-3660 php: FastCGI module DoS via multiple dots preceding the extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478425" id="478425">CVE-2008-5498 php: libgd imagerotate() array index error memory disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478848" id="478848">CVE-2008-5557 php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479272" id="479272">CVE-2009-0754 PHP mbstring.func_overload web server denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480167" id="480167">CVE-2008-5814 php: XSS via PHP error messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338036" comment="php-common is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338037" comment="php-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338016" comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338017" comment="php-soap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338014" comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338015" comment="php-gd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338010" comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338011" comment="php-odbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338032" comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338033" comment="php-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338002" comment="php is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338003" comment="php is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338004" comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338005" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338012" comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338013" comment="php-cli is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338026" comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338027" comment="php-mbstring is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338028" comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338029" comment="php-xml is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338020" comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338021" comment="php-pgsql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338022" comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338023" comment="php-dba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338008" comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338009" comment="php-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338034" comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338035" comment="php-imap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338024" comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338025" comment="php-bcmath is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338018" comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338019" comment="php-ncurses is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338006" comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338007" comment="php-snmp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338038" comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338039" comment="php-ldap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338030" comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338031" comment="php-pdo is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090339" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0339: lcms security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0339-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0339.html" />
          <reference source="CVE" ref_id="CVE-2009-0581" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0581.html" />
          <reference source="CVE" ref_id="CVE-2009-0723" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0723.html" />
          <reference source="CVE" ref_id="CVE-2009-0733" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0733.html" />
    
    <description>Little Color Management System (LittleCMS, or simply "lcms") is a
small-footprint, speed-optimized open source color management engine.

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in LittleCMS. An attacker could use these flaws to create a
specially-crafted image file which could cause an application using
LittleCMS to crash, or, possibly, execute arbitrary code when opened by a
victim. (CVE-2009-0723, CVE-2009-0733)

A memory leak flaw was found in LittleCMS. An application using LittleCMS
could use excessive amount of memory, and possibly crash after using all
available memory, if used to open specially-crafted images. (CVE-2009-0581)

Red Hat would like to thank Chris Evans from the Google Security Team for
reporting these issues.

All users of LittleCMS should install these updated packages, which upgrade
LittleCMS to version 1.18. All running applications using the lcms library
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0581.html">CVE-2009-0581</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0723.html">CVE-2009-0723</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0733.html">CVE-2009-0733</cve>
                <bugzilla href="http://bugzilla.redhat.com/487508" id="487508">CVE-2009-0723 LittleCms integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487509" id="487509">CVE-2009-0581 LittleCms memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487512" id="487512">CVE-2009-0733 LittleCms lack of upper-bounds check on sizes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090339002" comment="lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011003" comment="lcms is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090339006" comment="lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011005" comment="lcms-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090339004" comment="python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011007" comment="python-lcms is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090340" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0340: libpng security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0340-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0340.html" />
          <reference source="CVE" ref_id="CVE-2009-0040" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0040.html" />
    
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was discovered in libpng that could result in libpng trying to
free() random memory if certain, unlikely error conditions occurred. If a
carefully-crafted PNG file was loaded by an application linked against
libpng, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-0040)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0040.html">CVE-2009-0040</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340002" comment="libpng is earlier than 2:1.2.2-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333008" comment="libpng is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340004" comment="libpng-devel is earlier than 2:1.2.2-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333010" comment="libpng-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340008" comment="libpng10-devel is earlier than 0:1.0.13-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333014" comment="libpng10-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340006" comment="libpng10 is earlier than 0:1.0.13-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333012" comment="libpng10 is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090341" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0341: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0341-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0341.html" />
          <reference source="CVE" ref_id="CVE-2009-0037" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0037.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

David Kierznowski discovered a flaw in libcurl where it would not
differentiate between different target URLs when handling automatic
redirects. This caused libcurl to follow any new URL that it understood,
including the "file://" URL type. This could allow a remote server to force
a local libcurl-using application to read a local file instead of the
remote one, possibly exposing local files that were not meant to be
exposed. (CVE-2009-0037)

Note: Applications using libcurl that are expected to follow redirects to
"file://" protocol must now explicitly call curl_easy_setopt(3) and set the
newly introduced CURLOPT_REDIR_PROTOCOLS option as required.

cURL users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
libcurl must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0037.html">CVE-2009-0037</cve>
                <bugzilla href="http://bugzilla.redhat.com/485271" id="485271">CVE-2009-0037 curl: local file access via unsafe redirects</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341002" comment="curl is earlier than 0:7.15.5-2.1.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341003" comment="curl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341004" comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341005" comment="curl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341007" comment="curl is earlier than 0:7.10.6-9.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341008" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341009" comment="curl-devel is earlier than 0:7.10.6-9.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341010" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341012" comment="curl is earlier than 0:7.12.1-11.1.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341008" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341013" comment="curl-devel is earlier than 0:7.12.1-11.1.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341010" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090344" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0344: libsoup security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0344.html" />
          <reference source="CVE" ref_id="CVE-2009-0585" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0585.html" />
    
    <description>libsoup is an HTTP client/library implementation for GNOME written in C. It
was originally part of a SOAP (Simple Object Access Protocol)
implementation called Soup, but the SOAP and non-SOAP parts have now been
split into separate packages.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in libsoup's Base64 encoding routine. An attacker could use this
flaw to crash, or, possibly, execute arbitrary code. This arbitrary code
would execute with the privileges of the application using libsoup's Base64
routine to encode large, untrusted inputs. (CVE-2009-0585)

All users of libsoup and evolution28-libsoup should upgrade to these
updated packages, which contain a backported patch to resolve this issue.
All running applications using the affected library function (such as
Evolution configured to connect to the GroupWise back-end) must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0585.html">CVE-2009-0585</cve>
                <bugzilla href="http://bugzilla.redhat.com/488026" id="488026">CVE-2009-0585 libsoup: integer overflow in soup_base64_encode()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344004" comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344005" comment="libsoup-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344002" comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344003" comment="libsoup is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344009" comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344010" comment="libsoup-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344007" comment="libsoup is earlier than 0:2.2.1-4.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344008" comment="libsoup is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344013" comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344014" comment="evolution28-libsoup-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344011" comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344012" comment="evolution28-libsoup is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090345" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0345: ghostscript security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0345-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0345.html" />
          <reference source="CVE" ref_id="CVE-2009-0583" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0583.html" />
          <reference source="CVE" ref_id="CVE-2009-0584" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0584.html" />
    
    <description>Ghostscript is a set of software that provides a PostScript(TM)
interpreter, a set of C procedures (the Ghostscript library, which
implements the graphics capabilities in the PostScript language) and
an interpreter for Portable Document Format (PDF) files. 

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in Ghostscript's International Color Consortium Format library
(icclib). Using specially-crafted ICC profiles, an attacker could create a
malicious PostScript or PDF file with embedded images which could cause
Ghostscript to crash, or, potentially, execute arbitrary code when opened
by the victim. (CVE-2009-0583, CVE-2009-0584)

All users of ghostscript are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0583.html">CVE-2009-0583</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0584.html">CVE-2009-0584</cve>
                <bugzilla href="http://bugzilla.redhat.com/487742" id="487742">CVE-2009-0583 ghostscript, argyllcms: Multiple integer overflows in the International Color Consortium Format Library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487744" id="487744">CVE-2009-0584 ghostscript, argyllcms: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345004" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345005" comment="ghostscript-gtk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345002" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345003" comment="ghostscript is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345006" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345007" comment="ghostscript-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345009" comment="ghostscript is earlier than 0:7.05-32.1.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345010" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345013" comment="ghostscript-devel is earlier than 0:7.05-32.1.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345014" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345011" comment="hpijs is earlier than 0:1.3-32.1.17" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345012" comment="hpijs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345017" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345018" comment="ghostscript-gtk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345016" comment="ghostscript is earlier than 0:7.07-33.2.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345010" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090345019" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345014" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090352" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0352: gstreamer-plugins-base security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0352-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0352.html" />
          <reference source="CVE" ref_id="CVE-2009-0586" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0586.html" />
    
    <description>GStreamer is a streaming media framework based on graphs of filters which
operate on media data. GStreamer Base Plug-ins is a collection of
well-maintained base plug-ins.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in the Vorbis comment tags reader. An attacker could create a
carefully-crafted Vorbis file that would cause an application using
GStreamer to crash or, potentially, execute arbitrary code if opened by a
victim. (CVE-2009-0586)

All users of gstreamer-plugins-base are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all applications using GStreamer (such as Totem or
Rhythmbox) must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-06" />
        <updated date="2009-04-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0586.html">CVE-2009-0586</cve>
                <bugzilla href="http://bugzilla.redhat.com/488208" id="488208">CVE-2009-0586 gstreamer-plugins-base: integer overflow in gst_vorbis_tag_add_coverart()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090352002" comment="gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090352003" comment="gstreamer-plugins-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090352004" comment="gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090352005" comment="gstreamer-plugins-base-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090354" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0354: evolution-data-server security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0354-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0354.html" />
          <reference source="CVE" ref_id="CVE-2009-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0547.html" />
          <reference source="CVE" ref_id="CVE-2009-0582" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0582.html" />
          <reference source="CVE" ref_id="CVE-2009-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0587.html" />
    
    <description>Evolution Data Server provides a unified back-end for applications which
interact with contacts, task, and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.

Evolution Data Server did not properly check the Secure/Multipurpose
Internet Mail Extensions (S/MIME) signatures used for public key encryption
and signing of e-mail messages. An attacker could use this flaw to spoof a
signature by modifying the text of the e-mail message displayed to the
user. (CVE-2009-0547)

It was discovered that Evolution Data Server did not properly validate NTLM
(NT LAN Manager) authentication challenge packets. A malicious server using
NTLM authentication could cause an application using Evolution Data Server
to disclose portions of its memory or crash during user authentication.
(CVE-2009-0582)

Multiple integer overflow flaws which could cause heap-based buffer
overflows were found in the Base64 encoding routines used by Evolution Data
Server. This could cause an application using Evolution Data Server to
crash, or, possibly, execute an arbitrary code when large untrusted data
blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution-data-server and evolution28-evolution-data-server
are advised to upgrade to these updated packages, which contain backported
patches to correct these issues. All running instances of Evolution Data
Server and applications using it (such as Evolution) must be restarted for
the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0547.html">CVE-2009-0547</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0582.html">CVE-2009-0582</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0587.html">CVE-2009-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/484925" id="484925">CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487685" id="487685">CVE-2009-0582 evolution-data-server: insufficient checking of NTLM authentication challenge packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488226" id="488226">CVE-2009-0587 evolution-data-server: integer overflow in base64 encoding functions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354006" comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354007" comment="evolution-data-server-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354002" comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354003" comment="evolution-data-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354004" comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354005" comment="evolution-data-server-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354009" comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354010" comment="evolution28-evolution-data-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354011" comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354012" comment="evolution28-evolution-data-server-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090355" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0355: evolution and evolution-data-server security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0355-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0355.html" />
          <reference source="CVE" ref_id="CVE-2009-0547" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0547.html" />
          <reference source="CVE" ref_id="CVE-2009-0582" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0582.html" />
          <reference source="CVE" ref_id="CVE-2009-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0587.html" />
    
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

Evolution Data Server provides a unified back-end for applications which
interact with contacts, task and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.

Evolution did not properly check the Secure/Multipurpose Internet Mail
Extensions (S/MIME) signatures used for public key encryption and signing
of e-mail messages. An attacker could use this flaw to spoof a signature by
modifying the text of the e-mail message displayed to the user. (CVE-2009-0547)

It was discovered that evolution did not properly validate NTLM (NT LAN
Manager) authentication challenge packets. A malicious server using NTLM
authentication could cause evolution to disclose portions of its memory or
crash during user authentication. (CVE-2009-0582)

Multiple integer overflow flaws which could cause heap-based buffer
overflows were found in the Base64 encoding routines used by evolution and
evolution-data-server. This could cause evolution, or an application using
evolution-data-server, to crash, or, possibly, execute an arbitrary code
when large untrusted data blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution and evolution-data-server are advised to upgrade to
these updated packages, which contain backported patches to correct these
issues. All running instances of evolution and evolution-data-server must
be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0547.html">CVE-2009-0547</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0582.html">CVE-2009-0582</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0587.html">CVE-2009-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/484925" id="484925">CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487685" id="487685">CVE-2009-0582 evolution-data-server: insufficient checking of NTLM authentication challenge packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488226" id="488226">CVE-2009-0587 evolution-data-server: integer overflow in base64 encoding functions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355002" comment="evolution is earlier than 0:2.0.2-41.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355004" comment="evolution-devel is earlier than 0:2.0.2-41.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355006" comment="evolution-data-server is earlier than 0:1.0.2-14.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355007" comment="evolution-data-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355008" comment="evolution-data-server-devel is earlier than 0:1.0.2-14.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355009" comment="evolution-data-server-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090358" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0358: evolution security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0358-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0358.html" />
          <reference source="CVE" ref_id="CVE-2009-0582" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0582.html" />
          <reference source="CVE" ref_id="CVE-2009-0587" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0587.html" />
    
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

It was discovered that evolution did not properly validate NTLM (NT LAN
Manager) authentication challenge packets. A malicious server using NTLM
authentication could cause evolution to disclose portions of its memory or
crash during user authentication. (CVE-2009-0582)

An integer overflow flaw which could cause heap-based buffer overflow was
found in the Base64 encoding routine used by evolution. This could cause
evolution to crash, or, possibly, execute an arbitrary code when large
untrusted data blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of evolution must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0582.html">CVE-2009-0582</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0587.html">CVE-2009-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/487685" id="487685">CVE-2009-0582 evolution-data-server: insufficient checking of NTLM authentication challenge packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488226" id="488226">CVE-2009-0587 evolution-data-server: integer overflow in base64 encoding functions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090358002" comment="evolution is earlier than 0:1.4.5-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355003" comment="evolution is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090358004" comment="evolution-devel is earlier than 0:1.4.5-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355005" comment="evolution-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090361" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0361: NetworkManager security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0361.html" />
          <reference source="CVE" ref_id="CVE-2009-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0365.html" />
          <reference source="CVE" ref_id="CVE-2009-0578" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0578.html" />
    
    <description>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)

A potential denial of service flaw was found in NetworkManager's D-Bus
interface. A local user could leverage this flaw to modify local connection
settings, preventing the system's network connection from functioning
properly. (CVE-2009-0578)

Red Hat would like to thank Ludwig Nussel for reporting these flaws
responsibly.

Users of NetworkManager should upgrade to these updated packages which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-25" />
        <updated date="2009-03-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0365.html">CVE-2009-0365</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0578.html">CVE-2009-0578</cve>
                <bugzilla href="http://bugzilla.redhat.com/487722" id="487722">CVE-2009-0365 NetworkManager: GetSecrets disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487752" id="487752">CVE-2009-0578 NetworkManager: local users can modify the connection settings</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361008" comment="NetworkManager-glib is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361009" comment="NetworkManager-glib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361010" comment="NetworkManager-gnome is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361011" comment="NetworkManager-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361006" comment="NetworkManager-devel is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361007" comment="NetworkManager-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361004" comment="NetworkManager-glib-devel is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361005" comment="NetworkManager-glib-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361002" comment="NetworkManager is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361003" comment="NetworkManager is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090362" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0362: NetworkManager security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0362-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0362.html" />
          <reference source="CVE" ref_id="CVE-2009-0365" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0365.html" />
    
    <description>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)

Red Hat would like to thank Ludwig Nussel for responsibly reporting this
flaw.

NetworkManager users should upgrade to these updated packages, which
contain a backported patch that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-25" />
        <updated date="2009-03-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0365.html">CVE-2009-0365</cve>
                <bugzilla href="http://bugzilla.redhat.com/487722" id="487722">CVE-2009-0365 NetworkManager: GetSecrets disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090362004" comment="NetworkManager-gnome is earlier than 0:0.3.1-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090362005" comment="NetworkManager-gnome is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090362002" comment="NetworkManager is earlier than 0:0.3.1-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090362003" comment="NetworkManager is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090369" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0369: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0369-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0369.html" />
          <reference source="CVE" ref_id="CVE-2008-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5340.html" />
          <reference source="CVE" ref_id="CVE-2008-5341" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5341.html" />
          <reference source="CVE" ref_id="CVE-2008-5342" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5342.html" />
          <reference source="CVE" ref_id="CVE-2008-5343" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5343.html" />
          <reference source="CVE" ref_id="CVE-2008-5351" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5351.html" />
          <reference source="CVE" ref_id="CVE-2008-5356" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5356.html" />
          <reference source="CVE" ref_id="CVE-2008-5357" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5357.html" />
          <reference source="CVE" ref_id="CVE-2008-5358" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5358.html" />
    
    <description>The IBM® 1.6.0 Java™ release includes the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2008-5340, CVE-2008-5341, CVE-2008-5342,
CVE-2008-5343, CVE-2008-5351, CVE-2008-5356, CVE-2008-5357, CVE-2008-5358)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR4 Java release. All running instances
of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-25" />
        <updated date="2009-03-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5340.html">CVE-2008-5340</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5341.html">CVE-2008-5341</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5342.html">CVE-2008-5342</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5343.html">CVE-2008-5343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5351.html">CVE-2008-5351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5356.html">CVE-2008-5356</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5357.html">CVE-2008-5357</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5358.html">CVE-2008-5358</cve>
                <bugzilla href="http://bugzilla.redhat.com/472213" id="472213">CVE-2008-5351 OpenJDK UTF-8 decoder accepts non-shortest form sequences (4486841)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472218" id="472218">CVE-2008-5356 OpenJDK Font processing vulnerability (6733336)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472231" id="472231">CVE-2008-5357 OpenJDK Truetype Font processing vulnerability (6751322)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472234" id="472234">CVE-2008-5358 OpenJDK Buffer Overflow in GIF image processing (6766136)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474773" id="474773">CVE-2008-5340 Java WebStart privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474786" id="474786">CVE-2008-5341 Java Web Start exposes username and the pathname of the JWS cache</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474789" id="474789">CVE-2008-5342 Java Web Start BasicService displays local files in the browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474790" id="474790">CVE-2008-5343 Java WebStart allows hidden code privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369012" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015011" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369016" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369006" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015007" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369014" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015005" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369008" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015017" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369010" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015013" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090369004" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.4-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015015" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090373" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0373: systemtap security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0373.html" />
          <reference source="CVE" ref_id="CVE-2009-0784" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0784.html" />
    
    <description>SystemTap is an instrumentation infrastructure for systems running version
2.6 of the Linux kernel. SystemTap scripts can collect system operations
data, greatly simplifying information gathering. Collected data can then
assist in performance measuring, functional testing, and performance and
function problem diagnosis.

A race condition was discovered in SystemTap that could allow users in the
stapusr group to elevate privileges to that of members of the stapdev group
(and hence root), bypassing directory confinement restrictions and allowing
them to insert arbitrary SystemTap kernel modules. (CVE-2009-0784)

Note: This issue was only exploitable if another SystemTap kernel module
was placed in the "systemtap/" module directory for the currently running
kernel.

Red Hat would like to thank Erik Sjölund for reporting this issue.

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-26" />
        <updated date="2009-03-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0784.html">CVE-2009-0784</cve>
                <bugzilla href="http://bugzilla.redhat.com/489808" id="489808">CVE-2009-0784 systemtap: race condition leads to privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373008" comment="systemtap-testsuite is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373009" comment="systemtap-testsuite is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373006" comment="systemtap-runtime is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373007" comment="systemtap-runtime is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373002" comment="systemtap is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373003" comment="systemtap is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373004" comment="systemtap-client is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373005" comment="systemtap-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373010" comment="systemtap-server is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373011" comment="systemtap-server is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373017" comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373018" comment="systemtap-testsuite is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373015" comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373016" comment="systemtap-runtime is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373013" comment="systemtap is earlier than 0:0.6.2-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373014" comment="systemtap is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090376" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0376: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0376-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0376.html" />
          <reference source="CVE" ref_id="CVE-2009-0193" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0193.html" />
          <reference source="CVE" ref_id="CVE-2009-0658" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0658.html" />
          <reference source="CVE" ref_id="CVE-2009-0928" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0928.html" />
          <reference source="CVE" ref_id="CVE-2009-1061" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1061.html" />
          <reference source="CVE" ref_id="CVE-2009-1062" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1062.html" />
    
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

Multiple input validation flaws were discovered in the JBIG2 compressed
images decoder used by Adobe Reader. A malicious PDF file could cause Adobe
Reader to crash or, potentially, execute arbitrary code as the user running
Adobe Reader. (CVE-2009-0193, CVE-2009-0658, CVE-2009-0928, CVE-2009-1061,
CVE-2009-1062)

All Adobe Reader users should install these updated packages. They contain
Adobe Reader version 8.1.4, which is not vulnerable to these issues. All
running instances of Adobe Reader must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-25" />
        <updated date="2009-03-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0193.html">CVE-2009-0193</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0658.html">CVE-2009-0658</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0928.html">CVE-2009-0928</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1061.html">CVE-2009-1061</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1062.html">CVE-2009-1062</cve>
                <bugzilla href="http://bugzilla.redhat.com/486928" id="486928">CVE-2009-0658, CVE-2009-0193, CVE-2009-0928, CVE-2009-1061, CVE-2009-1062 acroread: multiple JBIG2-related security flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090376004" comment="acroread-plugin is earlier than 0:8.1.4-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090376002" comment="acroread is earlier than 0:8.1.4-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090377" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0377: java-1.6.0-openjdk security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" />
          <reference source="CVE" ref_id="CVE-2006-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2426.html" />
          <reference source="CVE" ref_id="CVE-2009-0581" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0581.html" />
          <reference source="CVE" ref_id="CVE-2009-0723" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0723.html" />
          <reference source="CVE" ref_id="CVE-2009-0733" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0733.html" />
          <reference source="CVE" ref_id="CVE-2009-0793" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0793.html" />
          <reference source="CVE" ref_id="CVE-2009-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1093.html" />
          <reference source="CVE" ref_id="CVE-2009-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1094.html" />
          <reference source="CVE" ref_id="CVE-2009-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1095.html" />
          <reference source="CVE" ref_id="CVE-2009-1096" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1096.html" />
          <reference source="CVE" ref_id="CVE-2009-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1097.html" />
          <reference source="CVE" ref_id="CVE-2009-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1098.html" />
          <reference source="CVE" ref_id="CVE-2009-1101" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1101.html" />
          <reference source="CVE" ref_id="CVE-2009-1102" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1102.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

A flaw was found in the way that the Java Virtual Machine (JVM) handled
temporary font files. A malicious applet could use this flaw to use large
amounts of disk space, causing a denial of service. (CVE-2006-2426)

A memory leak flaw was found in LittleCMS (embedded in OpenJDK). An
application using color profiles could use excessive amounts of memory, and
possibly crash after using all available memory, if used to open
specially-crafted images. (CVE-2009-0581)

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in the way LittleCMS handled color profiles. An attacker could use
these flaws to create a specially-crafted image file which could cause a
Java application to crash or, possibly, execute arbitrary code when opened.
(CVE-2009-0723, CVE-2009-0733)

A null pointer dereference flaw was found in LittleCMS. An application
using color profiles could crash while converting a specially-crafted image
file. (CVE-2009-0793)

A flaw in the Java API for XML Web Services (JAX-WS) service endpoint
handling could allow a remote attacker to cause a denial of service on the
server application hosting the JAX-WS service endpoint. (CVE-2009-1101)

A flaw in the way the Java Runtime Environment initialized LDAP connections
could allow a remote, authenticated user to cause a denial of service on
the LDAP service. (CVE-2009-1093)

A flaw in the Java Runtime Environment LDAP client could allow malicious
data from an LDAP server to cause arbitrary code to be loaded and then run
on an LDAP client. (CVE-2009-1094)

Several buffer overflow flaws were found in the Java Runtime Environment
unpack200 functionality. An untrusted applet could extend its privileges,
allowing it to read and write local files, as well as to execute local
applications with the privileges of the user running the applet.
(CVE-2009-1095, CVE-2009-1096)

A flaw in the Java Runtime Environment Virtual Machine code generation
functionality could allow untrusted applets to extend their privileges. An
untrusted applet could extend its privileges, allowing it to read and write
local files, as well as execute local applications with the privileges
of the user running the applet. (CVE-2009-1102)

A buffer overflow flaw was found in the splash screen processing. A remote
attacker could extend privileges to read and write local files, as well as
to execute local applications with the privileges of the user running the
java process. (CVE-2009-1097)

A buffer overflow flaw was found in how GIF images were processed. A remote
attacker could extend privileges to read and write local files, as well as
execute local applications with the privileges of the user running the
java process. (CVE-2009-1098)

Note: The flaws concerning applets in this advisory, CVE-2009-1095,
CVE-2009-1096, and CVE-2009-1102, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2426.html">CVE-2006-2426</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0581.html">CVE-2009-0581</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0723.html">CVE-2009-0723</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0733.html">CVE-2009-0733</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0793.html">CVE-2009-0793</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1093.html">CVE-2009-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1094.html">CVE-2009-1094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1095.html">CVE-2009-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1096.html">CVE-2009-1096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1097.html">CVE-2009-1097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1098.html">CVE-2009-1098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1101.html">CVE-2009-1101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1102.html">CVE-2009-1102</cve>
                <bugzilla href="http://bugzilla.redhat.com/395481" id="395481">CVE-2006-2426 Untrusted applet causes DoS by filling up disk space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487508" id="487508">CVE-2009-0723 LittleCms integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487509" id="487509">CVE-2009-0581 LittleCms memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487512" id="487512">CVE-2009-0733 LittleCms lack of upper-bounds check on sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490166" id="490166">CVE-2009-1101 OpenJDK JAX-WS service endpoint remote Denial-of-Service (6630639)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490167" id="490167">CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service (6717680)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490168" id="490168">CVE-2009-1094 OpenJDK  LDAP client remote code execution (6737315)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490169" id="490169">CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490172" id="490172">CVE-2009-1102 OpenJDK code generation vulnerability (6636360)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490174" id="490174">CVE-2009-1097 OpenJDK PNG processing buffer overflow vulnerability (6804996)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490178" id="490178">CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability (6804998)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492353" id="492353">CVE-2009-0793 lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377008" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377009" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377010" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377004" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377005" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377006" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377007" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090382" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0382: libvirt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0382-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0382.html" />
          <reference source="CVE" ref_id="CVE-2008-5086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5086.html" />
          <reference source="CVE" ref_id="CVE-2009-0036" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0036.html" />
    
    <description>libvirt is a C API for managing and interacting with the virtualization
capabilities of Linux and other operating systems. libvirt also provides
tools for remotely managing virtualized systems.

The libvirtd daemon was discovered to not properly check user connection
permissions before performing certain privileged actions, such as
requesting migration of an unprivileged guest domain to another system. A
local user able to establish a read-only connection to libvirtd could use
this flaw to perform actions that should be restricted to read-write
connections. (CVE-2008-5086)

libvirt_proxy, a setuid helper application allowing non-privileged users to
communicate with the hypervisor, was discovered to not properly validate
user requests. Local users could use this flaw to cause a stack-based
buffer overflow in libvirt_proxy, possibly allowing them to run arbitrary
code with root privileges. (CVE-2009-0036)

All users are advised to upgrade to these updated packages, which contain
backported patches which resolve these issues. After installing the update,
libvirtd must be restarted manually (for example, by issuing a
"service libvirtd restart" command) for this change to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5086.html">CVE-2008-5086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0036.html">CVE-2009-0036</cve>
                <bugzilla href="http://bugzilla.redhat.com/476560" id="476560">CVE-2008-5086 libvirt: missing checks for read-only connection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484947" id="484947">CVE-2009-0036 libvirt: libvirt_proxy buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090045006" comment="libvirt-devel is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090045007" comment="libvirt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090045002" comment="libvirt is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090045003" comment="libvirt is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090045004" comment="libvirt-python is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090045005" comment="libvirt-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090392" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0392: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0392-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0392.html" />
          <reference source="CVE" ref_id="CVE-2006-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2426.html" />
          <reference source="CVE" ref_id="CVE-2009-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1093.html" />
          <reference source="CVE" ref_id="CVE-2009-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1094.html" />
          <reference source="CVE" ref_id="CVE-2009-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1095.html" />
          <reference source="CVE" ref_id="CVE-2009-1096" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1096.html" />
          <reference source="CVE" ref_id="CVE-2009-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1097.html" />
          <reference source="CVE" ref_id="CVE-2009-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1098.html" />
          <reference source="CVE" ref_id="CVE-2009-1099" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1099.html" />
          <reference source="CVE" ref_id="CVE-2009-1100" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1100.html" />
          <reference source="CVE" ref_id="CVE-2009-1101" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1101.html" />
          <reference source="CVE" ref_id="CVE-2009-1102" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1102.html" />
          <reference source="CVE" ref_id="CVE-2009-1103" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1103.html" />
          <reference source="CVE" ref_id="CVE-2009-1104" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1104.html" />
          <reference source="CVE" ref_id="CVE-2009-1105" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1105.html" />
          <reference source="CVE" ref_id="CVE-2009-1106" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1106.html" />
          <reference source="CVE" ref_id="CVE-2009-1107" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1107.html" />
    
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2006-2426, CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100,
CVE-2009-1101, CVE-2009-1102, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105,
CVE-2009-1106, CVE-2009-1107)

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-26" />
        <updated date="2009-03-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2426.html">CVE-2006-2426</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1093.html">CVE-2009-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1094.html">CVE-2009-1094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1095.html">CVE-2009-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1096.html">CVE-2009-1096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1097.html">CVE-2009-1097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1098.html">CVE-2009-1098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1099.html">CVE-2009-1099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1100.html">CVE-2009-1100</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1101.html">CVE-2009-1101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1102.html">CVE-2009-1102</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1103.html">CVE-2009-1103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1104.html">CVE-2009-1104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1105.html">CVE-2009-1105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1106.html">CVE-2009-1106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1107.html">CVE-2009-1107</cve>
                <bugzilla href="http://bugzilla.redhat.com/395481" id="395481">CVE-2006-2426 Untrusted applet causes DoS by filling up disk space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490166" id="490166">CVE-2009-1101 OpenJDK JAX-WS service endpoint remote Denial-of-Service (6630639)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490167" id="490167">CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service (6717680)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490168" id="490168">CVE-2009-1094 OpenJDK  LDAP client remote code execution (6737315)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490169" id="490169">CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490172" id="490172">CVE-2009-1102 OpenJDK code generation vulnerability (6636360)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490174" id="490174">CVE-2009-1097 OpenJDK PNG processing buffer overflow vulnerability (6804996)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490178" id="490178">CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability (6804998)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492302" id="492302">CVE-2009-1099 OpenJDK: Type1 font processing buffer overflow vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492305" id="492305">CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492306" id="492306">CVE-2009-1103 OpenJDK: Files disclosure, arbitrary code execution via "deserializing applets" (6646860)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492308" id="492308">CVE-2009-1104 OpenJDK: Intended access restrictions bypass via LiveConnect (6724331)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492309" id="492309">CVE-2009-1105 OpenJDK: Possibility of trusted applet run in older, vulnerable version of JRE (6706490)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492310" id="492310">CVE-2009-1106 OpenJDK: Improper parsing of crossdomain.xml files (intended access restriction bypass) (6798948)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492312" id="492312">CVE-2009-1107 OpenJDK: Signed applet remote misuse possibility (6782871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090392006" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392007" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090392002" comment="java-1.6.0-sun is earlier than 1:1.6.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090392010" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392011" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090392012" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392013" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090392004" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392005" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090392008" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392009" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090394" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0394: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0394-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0394.html" />
          <reference source="CVE" ref_id="CVE-2006-2426" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-2426.html" />
          <reference source="CVE" ref_id="CVE-2009-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1093.html" />
          <reference source="CVE" ref_id="CVE-2009-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1094.html" />
          <reference source="CVE" ref_id="CVE-2009-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1095.html" />
          <reference source="CVE" ref_id="CVE-2009-1096" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1096.html" />
          <reference source="CVE" ref_id="CVE-2009-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1098.html" />
          <reference source="CVE" ref_id="CVE-2009-1099" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1099.html" />
          <reference source="CVE" ref_id="CVE-2009-1100" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1100.html" />
          <reference source="CVE" ref_id="CVE-2009-1103" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1103.html" />
          <reference source="CVE" ref_id="CVE-2009-1104" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1104.html" />
          <reference source="CVE" ref_id="CVE-2009-1107" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1107.html" />
    
    <description>The Sun 1.5.0 Java release includes the Sun Java 5 Runtime Environment and
the Sun Java 5 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 5 Runtime
Environment and the Sun Java 5 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2006-2426, CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
CVE-2009-1096, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100, CVE-2009-1103,
CVE-2009-1104, CVE-2009-1107)

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-26" />
        <updated date="2009-03-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-2426.html">CVE-2006-2426</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1093.html">CVE-2009-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1094.html">CVE-2009-1094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1095.html">CVE-2009-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1096.html">CVE-2009-1096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1098.html">CVE-2009-1098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1099.html">CVE-2009-1099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1100.html">CVE-2009-1100</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1103.html">CVE-2009-1103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1104.html">CVE-2009-1104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1107.html">CVE-2009-1107</cve>
                <bugzilla href="http://bugzilla.redhat.com/395481" id="395481">CVE-2006-2426 Untrusted applet causes DoS by filling up disk space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490167" id="490167">CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service (6717680)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490168" id="490168">CVE-2009-1094 OpenJDK  LDAP client remote code execution (6737315)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490169" id="490169">CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490178" id="490178">CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability (6804998)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492302" id="492302">CVE-2009-1099 OpenJDK: Type1 font processing buffer overflow vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492305" id="492305">CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492306" id="492306">CVE-2009-1103 OpenJDK: Files disclosure, arbitrary code execution via "deserializing applets" (6646860)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492308" id="492308">CVE-2009-1104 OpenJDK: Intended access restrictions bypass via LiveConnect (6724331)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492312" id="492312">CVE-2009-1107 OpenJDK: Signed applet remote misuse possibility (6782871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090394012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.18-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090394002" comment="java-1.5.0-sun is earlier than 0:1.5.0.18-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090394008" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.18-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394009" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090394006" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.18-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090394004" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.18-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394005" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090394010" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.18-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394011" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090397" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0397: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0397-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0397.html" />
          <reference source="CVE" ref_id="CVE-2009-1044" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1044.html" />
          <reference source="CVE" ref_id="CVE-2009-1169" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1169.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A memory corruption flaw was discovered in the way Firefox handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2009-1169)

A flaw was discovered in the way Firefox handles certain XUL garbage
collection events. A remote attacker could use this flaw to crash Firefox
or, potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1044)

For technical details regarding these flaws, refer to the Mozilla security
advisories. You can find a link to the Mozilla advisories in the References
section of this errata.

Firefox users should upgrade to these updated packages, which resolve these
issues. For Red Hat Enterprise Linux 4, they contain backported patches to
the firefox package. For Red Hat Enterprise Linux 5, they contain
backported patches to the xulrunner packages. After installing the update,
Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-27" />
        <updated date="2009-03-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1044.html">CVE-2009-1044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1169.html">CVE-2009-1169</cve>
                <bugzilla href="http://bugzilla.redhat.com/492211" id="492211">CVE-2009-1169 Firefox XSLT memory corruption issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492212" id="492212">CVE-2009-1044 Firefox XUL garbage collection issue (cansecwest pwn2own)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090397006" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090397002" comment="xulrunner is earlier than 0:1.9.0.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090397004" comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090397009" comment="firefox is earlier than 0:3.0.7-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090398" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0398: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0398-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0398.html" />
          <reference source="CVE" ref_id="CVE-2009-1044" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1044.html" />
          <reference source="CVE" ref_id="CVE-2009-1169" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1169.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A memory corruption flaw was discovered in the way SeaMonkey handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash SeaMonkey or, potentially, execute arbitrary code as the user
running SeaMonkey. (CVE-2009-1169)

A flaw was discovered in the way SeaMonkey handles certain XUL garbage
collection events. A remote attacker could use this flaw to crash SeaMonkey
or, potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1044)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-27" />
        <updated date="2009-03-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1044.html">CVE-2009-1044</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1169.html">CVE-2009-1169</cve>
                <bugzilla href="http://bugzilla.redhat.com/492211" id="492211">CVE-2009-1169 Firefox XSLT memory corruption issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492212" id="492212">CVE-2009-1044 Firefox XUL garbage collection issue (cansecwest pwn2own)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398012" comment="seamonkey-nspr is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398010" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398004" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398016" comment="seamonkey-mail is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398002" comment="seamonkey is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398008" comment="seamonkey-devel is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398020" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398014" comment="seamonkey-chat is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398006" comment="seamonkey-nss is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398018" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398027" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398026" comment="seamonkey-mail is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398023" comment="seamonkey is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398024" comment="seamonkey-devel is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398025" comment="seamonkey-chat is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398028" comment="seamonkey-js-debugger is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090402" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0402: openswan security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0402.html" />
          <reference source="CVE" ref_id="CVE-2008-4190" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4190.html" />
          <reference source="CVE" ref_id="CVE-2009-0790" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0790.html" />
    
    <description>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).

Gerd v. Egidy discovered a flaw in the Dead Peer Detection (DPD) in
Openswan's pluto IKE daemon. A remote attacker could use a malicious DPD
packet to crash the pluto daemon. (CVE-2009-0790)

It was discovered that Openswan's livetest script created temporary files
in an insecure manner. A local attacker could use this flaw to overwrite
arbitrary files owned by the user running the script. (CVE-2008-4190)

Note: The livetest script is an incomplete feature and was not
automatically executed by any other script distributed with Openswan, or
intended to be used at all, as was documented in its man page. In these
updated packages, the script only prints an informative message and exits
immediately when run.

All users of openswan are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the ipsec service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-30" />
        <updated date="2009-03-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4190.html">CVE-2008-4190</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0790.html">CVE-2009-0790</cve>
                <bugzilla href="http://bugzilla.redhat.com/460425" id="460425">CVE-2008-4190 openswan: Insecure auxiliary /tmp file usage (symlink attack possible)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491895" id="491895">CVE-2009-0790 openswan: ISAKMP DPD remote DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090402002" comment="openswan is earlier than 0:2.6.14-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090402003" comment="openswan is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090402004" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090402005" comment="openswan-doc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090408" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0408: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0408-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0408.html" />
          <reference source="CVE" ref_id="CVE-2009-0844" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0844.html" />
          <reference source="CVE" ref_id="CVE-2009-0845" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0845.html" />
          <reference source="CVE" ref_id="CVE-2009-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0846.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC). The Generic
Security Service Application Program Interface (GSS-API) definition
provides security services to callers (protocols) in a generic fashion. The
Simple and Protected GSS-API Negotiation (SPNEGO) mechanism is used by
GSS-API peers to choose from a common set of security mechanisms.

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)

Multiple input validation flaws were found in the MIT Kerberos GSS-API
library's implementation of the SPNEGO mechanism. A remote attacker could
use these flaws to crash any network service utilizing the MIT Kerberos
GSS-API library to authenticate users or, possibly, leak portions of the
service's memory. (CVE-2009-0844, CVE-2009-0845)

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running services using the
MIT Kerberos libraries must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0844.html">CVE-2009-0844</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0845.html">CVE-2009-0845</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0846.html">CVE-2009-0846</cve>
                <bugzilla href="http://bugzilla.redhat.com/490634" id="490634">CVE-2009-0845 krb5: NULL pointer dereference in GSSAPI SPNEGO (MITKRB5-SA-2009-001)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491033" id="491033">CVE-2009-0844 krb5: buffer over-read in SPNEGO GSS-API mechanism (MITKRB5-SA-2009-001)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491036" id="491036">CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408008" comment="krb5-libs is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408009" comment="krb5-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408006" comment="krb5-devel is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408007" comment="krb5-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408010" comment="krb5-server is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408011" comment="krb5-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408002" comment="krb5 is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408003" comment="krb5 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408004" comment="krb5-workstation is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090409" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0409: krb5 security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0409.html" />
          <reference source="CVE" ref_id="CVE-2009-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0846.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running services using the MIT
Kerberos libraries must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0846.html">CVE-2009-0846</cve>
                <bugzilla href="http://bugzilla.redhat.com/491036" id="491036">CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409006" comment="krb5-libs is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409004" comment="krb5-devel is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409010" comment="krb5-server is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409011" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409002" comment="krb5 is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409008" comment="krb5-workstation is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409009" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090410" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0410: krb5 security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0410-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0410.html" />
          <reference source="CVE" ref_id="CVE-2009-0846" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0846.html" />
    
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer or,
possibly, execute arbitrary code with the privileges of the user running
the service. (CVE-2009-0846)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running services using the MIT
Kerberos libraries must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0846.html">CVE-2009-0846</cve>
                <bugzilla href="http://bugzilla.redhat.com/491036" id="491036">CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410006" comment="krb5-libs is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409007" comment="krb5-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410010" comment="krb5-devel is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409005" comment="krb5-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410008" comment="krb5-server is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409011" comment="krb5-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410002" comment="krb5 is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409003" comment="krb5 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410004" comment="krb5-workstation is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409009" comment="krb5-workstation is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090411" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0411: device-mapper-multipath security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0411-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0411.html" />
          <reference source="CVE" ref_id="CVE-2009-0115" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0115.html" />
    
    <description>The device-mapper multipath packages provide tools to manage multipath
devices by issuing instructions to the device-mapper multipath kernel
module, and by managing the creation and removal of partitions for
device-mapper devices.

It was discovered that the multipathd daemon set incorrect permissions on
the socket used to communicate with command line clients. An unprivileged,
local user could use this flaw to send commands to multipathd, resulting in
access disruptions to storage devices accessible via multiple paths and,
possibly, file system corruption on these devices. (CVE-2009-0115)

Users of device-mapper-multipath are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. The
multipathd service must be restarted for the changes to take effect.

Important: the version of the multipathd daemon in Red Hat Enterprise Linux
5 has a known issue which may cause a machine to become unresponsive when
the multipathd service is stopped. This issue is tracked in the Bugzilla
bug #494582; a link is provided in the References section of this erratum.
Until this issue is resolved, we recommend restarting the multipathd
service by issuing the following commands in sequence:

	# killall -KILL multipathd

	# service multipathd restart</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0115.html">CVE-2009-0115</cve>
                <bugzilla href="http://bugzilla.redhat.com/493330" id="493330">CVE-2009-0115 device-mapper-multipath: insecure permissions on multipathd.sock</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090411004" comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411005" comment="kpartx is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090411002" comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411003" comment="device-mapper-multipath is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411007" comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411008" comment="device-mapper-multipath is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090420" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0420: ghostscript security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0420-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0420.html" />
          <reference source="CVE" ref_id="CVE-2007-6725" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6725.html" />
          <reference source="CVE" ref_id="CVE-2009-0792" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0792.html" />
    
    <description>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

It was discovered that the Red Hat Security Advisory RHSA-2009:0345 did not
address all possible integer overflow flaws in Ghostscript's International
Color Consortium Format library (icclib). Using specially-crafted ICC
profiles, an attacker could create a malicious PostScript or PDF file with
embedded images that could cause Ghostscript to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0792)

A missing boundary check was found in Ghostscript's CCITTFax decoding
filter. An attacker could create a specially-crafted PostScript or PDF file
that could cause Ghostscript to crash or, potentially, execute arbitrary
code when opened. (CVE-2007-6725)

Users of ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-14" />
        <updated date="2009-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6725.html">CVE-2007-6725</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0792.html">CVE-2009-0792</cve>
                <bugzilla href="http://bugzilla.redhat.com/491853" id="491853">CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493442" id="493442">CVE-2007-6725 ghostscript: DoS (crash) in CCITTFax decoding filter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090420002" comment="ghostscript is earlier than 0:7.05-32.1.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345010" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090420004" comment="ghostscript-devel is earlier than 0:7.05-32.1.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345014" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090420006" comment="hpijs is earlier than 0:1.3-32.1.20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345012" comment="hpijs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090420011" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345018" comment="ghostscript-gtk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090420009" comment="ghostscript is earlier than 0:7.07-33.2.el4_7.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345010" comment="ghostscript is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090420010" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345014" comment="ghostscript-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090421" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0421: ghostscript security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0421-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0421.html" />
          <reference source="CVE" ref_id="CVE-2007-6725" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-6725.html" />
          <reference source="CVE" ref_id="CVE-2008-6679" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6679.html" />
          <reference source="CVE" ref_id="CVE-2009-0196" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0196.html" />
          <reference source="CVE" ref_id="CVE-2009-0792" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0792.html" />
    
    <description>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

It was discovered that the Red Hat Security Advisory RHSA-2009:0345 did not
address all possible integer overflow flaws in Ghostscript's International
Color Consortium Format library (icclib). Using specially-crafted ICC
profiles, an attacker could create a malicious PostScript or PDF file with
embedded images that could cause Ghostscript to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0792)

A buffer overflow flaw and multiple missing boundary checks were found in
Ghostscript. An attacker could create a specially-crafted PostScript or PDF
file that could cause Ghostscript to crash or, potentially, execute
arbitrary code when opened. (CVE-2008-6679, CVE-2007-6725, CVE-2009-0196)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly reporting the CVE-2009-0196 flaw.

Users of ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-14" />
        <updated date="2009-04-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-6725.html">CVE-2007-6725</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6679.html">CVE-2008-6679</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0196.html">CVE-2009-0196</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0792.html">CVE-2009-0792</cve>
                <bugzilla href="http://bugzilla.redhat.com/491853" id="491853">CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493379" id="493379">CVE-2009-0196 ghostscript: Missing boundary check in Ghostscript's jbig2dec library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493442" id="493442">CVE-2007-6725 ghostscript: DoS (crash) in CCITTFax decoding filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493445" id="493445">CVE-2008-6679 ghostscript: Buffer overflow in BaseFont writer module for pdfwrite device</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090421006" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345005" comment="ghostscript-gtk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090421002" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345003" comment="ghostscript is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090421004" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090345007" comment="ghostscript-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090427" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0427: udev security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0427.html" />
          <reference source="CVE" ref_id="CVE-2009-1185" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1185.html" />
    
    <description>udev provides a user-space API and implements a dynamic device directory,
providing only the devices present on the system. udev replaces devfs in
order to provide greater hot plug functionality. Netlink is a datagram
oriented service, used to transfer information between kernel modules and
user-space processes.

It was discovered that udev did not properly check the origin of Netlink
messages. A local attacker could use this flaw to gain root privileges via
a crafted Netlink message sent to udev, causing it to create a
world-writable block device file for an existing system block device (for
example, the root file system). (CVE-2009-1185)

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
responsibly reporting this flaw.

Users of udev are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the udevd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1185.html">CVE-2009-1185</cve>
                <bugzilla href="http://bugzilla.redhat.com/495051" id="495051">CVE-2009-1185 udev: Uncheck origin of NETLINK messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090427002" comment="udev is earlier than 0:095-14.20.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090427003" comment="udev is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090427006" comment="libvolume_id is earlier than 0:095-14.20.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090427007" comment="libvolume_id is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090427004" comment="libvolume_id-devel is earlier than 0:095-14.20.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090427005" comment="libvolume_id-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090428" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0428: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0428-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0428.html" />
          <reference source="CVE" ref_id="CVE-2009-0163" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0163.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An integer overflow flaw, leading to a heap-based buffer overflow, was
discovered in the Tagged Image File Format (TIFF) decoding routines used by
the CUPS image-converting filters, "imagetops" and "imagetoraster". An
attacker could create a malicious TIFF file that could, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0163)

Red Hat would like to thank Aaron Sigel of the Apple Product Security team
for responsibly reporting this flaw.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0163.html">CVE-2009-0163</cve>
                <bugzilla href="http://bugzilla.redhat.com/490596" id="490596">CVE-2009-0163 cups: Integer overflow in the TIFF image filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491864" id="491864">Multiple PDF flaws</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090428004" comment="cups-devel is earlier than 1:1.1.17-13.3.58" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090428006" comment="cups-libs is earlier than 1:1.1.17-13.3.58" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090428002" comment="cups is earlier than 1:1.1.17-13.3.58" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090429" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0429: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0429.html" />
          <reference source="CVE" ref_id="CVE-2009-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0146.html" />
          <reference source="CVE" ref_id="CVE-2009-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0147.html" />
          <reference source="CVE" ref_id="CVE-2009-0163" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0163.html" />
          <reference source="CVE" ref_id="CVE-2009-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0166.html" />
          <reference source="CVE" ref_id="CVE-2009-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0195.html" />
          <reference source="CVE" ref_id="CVE-2009-0799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0799.html" />
          <reference source="CVE" ref_id="CVE-2009-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0800.html" />
          <reference source="CVE" ref_id="CVE-2009-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1179.html" />
          <reference source="CVE" ref_id="CVE-2009-1180" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1180.html" />
          <reference source="CVE" ref_id="CVE-2009-1181" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1181.html" />
          <reference source="CVE" ref_id="CVE-2009-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1182.html" />
          <reference source="CVE" ref_id="CVE-2009-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1183.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

Multiple integer overflow flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0147, CVE-2009-1179)

Multiple buffer overflow flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in the CUPS JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause CUPS to crash or, potentially, execute arbitrary code
as the "lp" user if the file was printed. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0800)

An integer overflow flaw, leading to a heap-based buffer overflow, was
discovered in the Tagged Image File Format (TIFF) decoding routines used by
the CUPS image-converting filters, "imagetops" and "imagetoraster". An
attacker could create a malicious TIFF file that could, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0163)

Multiple denial of service flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
when printed. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Aaron Sigel, Braden Thomas and Drew Yao of
the Apple Product Security team, and Will Dormann of the CERT/CC for
responsibly reporting these flaws.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0146.html">CVE-2009-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0147.html">CVE-2009-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0163.html">CVE-2009-0163</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0166.html">CVE-2009-0166</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0195.html">CVE-2009-0195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0799.html">CVE-2009-0799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0800.html">CVE-2009-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1179.html">CVE-2009-1179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1180.html">CVE-2009-1180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1181.html">CVE-2009-1181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1182.html">CVE-2009-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1183.html">CVE-2009-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/490596" id="490596">CVE-2009-0163 cups: Integer overflow in the TIFF image filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491864" id="491864">Multiple PDF flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429006" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429004" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429008" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429002" comment="cups is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429015" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429013" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429011" comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090430" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0430: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0430.html" />
          <reference source="CVE" ref_id="CVE-2009-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0146.html" />
          <reference source="CVE" ref_id="CVE-2009-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0147.html" />
          <reference source="CVE" ref_id="CVE-2009-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0166.html" />
          <reference source="CVE" ref_id="CVE-2009-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0195.html" />
          <reference source="CVE" ref_id="CVE-2009-0799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0799.html" />
          <reference source="CVE" ref_id="CVE-2009-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0800.html" />
          <reference source="CVE" ref_id="CVE-2009-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1179.html" />
          <reference source="CVE" ref_id="CVE-2009-1180" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1180.html" />
          <reference source="CVE" ref_id="CVE-2009-1181" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1181.html" />
          <reference source="CVE" ref_id="CVE-2009-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1182.html" />
          <reference source="CVE" ref_id="CVE-2009-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1183.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in Xpdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause Xpdf to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF that would cause Xpdf to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0146.html">CVE-2009-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0147.html">CVE-2009-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0166.html">CVE-2009-0166</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0195.html">CVE-2009-0195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0799.html">CVE-2009-0799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0800.html">CVE-2009-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1179.html">CVE-2009-1179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1180.html">CVE-2009-1180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1181.html">CVE-2009-1181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1182.html">CVE-2009-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1183.html">CVE-2009-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491864" id="491864">Multiple PDF flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430002" comment="xpdf is earlier than 1:2.02-14.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430005" comment="xpdf is earlier than 1:3.00-20.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090431" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0431: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0431-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0431.html" />
          <reference source="CVE" ref_id="CVE-2009-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0146.html" />
          <reference source="CVE" ref_id="CVE-2009-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0147.html" />
          <reference source="CVE" ref_id="CVE-2009-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0166.html" />
          <reference source="CVE" ref_id="CVE-2009-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0195.html" />
          <reference source="CVE" ref_id="CVE-2009-0799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0799.html" />
          <reference source="CVE" ref_id="CVE-2009-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0800.html" />
          <reference source="CVE" ref_id="CVE-2009-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1179.html" />
          <reference source="CVE" ref_id="CVE-2009-1180" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1180.html" />
          <reference source="CVE" ref_id="CVE-2009-1181" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1181.html" />
          <reference source="CVE" ref_id="CVE-2009-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1182.html" />
          <reference source="CVE" ref_id="CVE-2009-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1183.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in KPDF's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause KPDF to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF that would cause KPDF to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0146.html">CVE-2009-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0147.html">CVE-2009-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0166.html">CVE-2009-0166</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0195.html">CVE-2009-0195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0799.html">CVE-2009-0799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0800.html">CVE-2009-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1179.html">CVE-2009-1179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1180.html">CVE-2009-1180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1181.html">CVE-2009-1181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1182.html">CVE-2009-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1183.html">CVE-2009-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491864" id="491864">Multiple PDF flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431002" comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431003" comment="kdegraphics is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431004" comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431005" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431007" comment="kdegraphics is earlier than 7:3.3.1-13.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431008" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431009" comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431010" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090436" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:0436: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0436-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0436.html" />
          <reference source="CVE" ref_id="CVE-2009-0652" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0652.html" />
          <reference source="CVE" ref_id="CVE-2009-1302" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1302.html" />
          <reference source="CVE" ref_id="CVE-2009-1303" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1303.html" />
          <reference source="CVE" ref_id="CVE-2009-1304" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1304.html" />
          <reference source="CVE" ref_id="CVE-2009-1305" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1305.html" />
          <reference source="CVE" ref_id="CVE-2009-1306" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1306.html" />
          <reference source="CVE" ref_id="CVE-2009-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1307.html" />
          <reference source="CVE" ref_id="CVE-2009-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1308.html" />
          <reference source="CVE" ref_id="CVE-2009-1309" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1309.html" />
          <reference source="CVE" ref_id="CVE-2009-1310" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1310.html" />
          <reference source="CVE" ref_id="CVE-2009-1311" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1311.html" />
          <reference source="CVE" ref_id="CVE-2009-1312" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1312.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1308, CVE-2009-1309, CVE-2009-1310,
CVE-2009-1312)

A flaw was found in the way Firefox saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.9. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.9, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-21" />
        <updated date="2009-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0652.html">CVE-2009-0652</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1302.html">CVE-2009-1302</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1303.html">CVE-2009-1303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1304.html">CVE-2009-1304</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1305.html">CVE-2009-1305</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1306.html">CVE-2009-1306</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1307.html">CVE-2009-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1308.html">CVE-2009-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1309.html">CVE-2009-1309</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1310.html">CVE-2009-1310</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1311.html">CVE-2009-1311</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1312.html">CVE-2009-1312</cve>
                <bugzilla href="http://bugzilla.redhat.com/486704" id="486704">CVE-2009-0652 firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496252" id="496252">CVE-2009-1302 Firefox 3 Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496253" id="496253">CVE-2009-1303 Firefox 2 and 3 Layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496255" id="496255">CVE-2009-1304 Firefox 3 JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496256" id="496256">CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496262" id="496262">CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496263" id="496263">CVE-2009-1307 Firefox Same-origin violations when Adobe Flash loaded via view-source: protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496266" id="496266">CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496267" id="496267">CVE-2009-1309 Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496270" id="496270">CVE-2009-1310 Firefox Malicious search plugins can inject code into arbitrary sites</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496271" id="496271">CVE-2009-1311 Firefox POST data sent to wrong site when saving web page with embedded frame</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496274" id="496274">CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436002" comment="xulrunner is earlier than 0:1.9.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436006" comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436008" comment="firefox is earlier than 0:3.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090436011" comment="firefox is earlier than 0:3.0.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090437" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:0437: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0437-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0437.html" />
          <reference source="CVE" ref_id="CVE-2009-0652" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0652.html" />
          <reference source="CVE" ref_id="CVE-2009-1303" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1303.html" />
          <reference source="CVE" ref_id="CVE-2009-1305" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1305.html" />
          <reference source="CVE" ref_id="CVE-2009-1306" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1306.html" />
          <reference source="CVE" ref_id="CVE-2009-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1307.html" />
          <reference source="CVE" ref_id="CVE-2009-1309" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1309.html" />
          <reference source="CVE" ref_id="CVE-2009-1311" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1311.html" />
          <reference source="CVE" ref_id="CVE-2009-1312" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1312.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1303, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1309, CVE-2009-1312)

A flaw was found in the way SeaMonkey saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-21" />
        <updated date="2009-04-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0652.html">CVE-2009-0652</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1303.html">CVE-2009-1303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1305.html">CVE-2009-1305</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1306.html">CVE-2009-1306</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1307.html">CVE-2009-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1309.html">CVE-2009-1309</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1311.html">CVE-2009-1311</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1312.html">CVE-2009-1312</cve>
                <bugzilla href="http://bugzilla.redhat.com/486704" id="486704">CVE-2009-0652 firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496253" id="496253">CVE-2009-1303 Firefox 2 and 3 Layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496256" id="496256">CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496262" id="496262">CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496263" id="496263">CVE-2009-1307 Firefox Same-origin violations when Adobe Flash loaded via view-source: protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496267" id="496267">CVE-2009-1309 Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496271" id="496271">CVE-2009-1311 Firefox POST data sent to wrong site when saving web page with embedded frame</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496274" id="496274">CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437016" comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437014" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437018" comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437002" comment="seamonkey is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437012" comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437020" comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437010" comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437004" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437006" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437025" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437026" comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437023" comment="seamonkey is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437024" comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437028" comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090444" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0444: giflib security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0444-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0444.html" />
          <reference source="CVE" ref_id="CVE-2005-2974" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-2974.html" />
          <reference source="CVE" ref_id="CVE-2005-3350" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-3350.html" />
    
    <description>The giflib packages contain a shared library of functions for loading and
saving GIF image files. This library is API and ABI compatible with
libungif, the library that supported uncompressed GIF image files while the
Unisys LZW patent was in effect.

Several flaws were discovered in the way giflib decodes GIF images. An
attacker could create a carefully crafted GIF image that could cause an
application using giflib to crash or, possibly, execute arbitrary code when
opened by a victim. (CVE-2005-2974, CVE-2005-3350)

All users of giflib are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications using giflib must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-22" />
        <updated date="2009-04-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-2974.html">CVE-2005-2974</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-3350.html">CVE-2005-3350</cve>
                <bugzilla href="http://bugzilla.redhat.com/494823" id="494823">CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494826" id="494826">CVE-2005-2974 giflib/libunfig: NULL pointer dereference crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090444004" comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090444005" comment="giflib-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090444002" comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090444003" comment="giflib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090444006" comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090444007" comment="giflib-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090445" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0445: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0445-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0445.html" />
          <reference source="CVE" ref_id="CVE-2008-2086" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2086.html" />
          <reference source="CVE" ref_id="CVE-2008-5339" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5339.html" />
          <reference source="CVE" ref_id="CVE-2008-5340" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5340.html" />
          <reference source="CVE" ref_id="CVE-2008-5342" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5342.html" />
          <reference source="CVE" ref_id="CVE-2008-5343" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5343.html" />
          <reference source="CVE" ref_id="CVE-2008-5344" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5344.html" />
          <reference source="CVE" ref_id="CVE-2008-5345" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5345.html" />
          <reference source="CVE" ref_id="CVE-2008-5346" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5346.html" />
          <reference source="CVE" ref_id="CVE-2008-5348" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5348.html" />
          <reference source="CVE" ref_id="CVE-2008-5350" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5350.html" />
          <reference source="CVE" ref_id="CVE-2008-5351" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5351.html" />
          <reference source="CVE" ref_id="CVE-2008-5353" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5353.html" />
          <reference source="CVE" ref_id="CVE-2008-5354" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5354.html" />
          <reference source="CVE" ref_id="CVE-2008-5359" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5359.html" />
          <reference source="CVE" ref_id="CVE-2008-5360" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5360.html" />
    
    <description>The IBM® 1.4.2 SR13 Java™ release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2008-2086, CVE-2008-5339, CVE-2008-5340,
CVE-2008-5342, CVE-2008-5343, CVE-2008-5344, CVE-2008-5345, CVE-2008-5346,
CVE-2008-5348, CVE-2008-5350, CVE-2008-5351, CVE-2008-5353, CVE-2008-5354,
CVE-2008-5359, CVE-2008-5360)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13 Java release. All running
instances of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-23" />
        <updated date="2009-04-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2086.html">CVE-2008-2086</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5339.html">CVE-2008-5339</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5340.html">CVE-2008-5340</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5342.html">CVE-2008-5342</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5343.html">CVE-2008-5343</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5344.html">CVE-2008-5344</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5345.html">CVE-2008-5345</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5346.html">CVE-2008-5346</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5348.html">CVE-2008-5348</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5350.html">CVE-2008-5350</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5351.html">CVE-2008-5351</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5353.html">CVE-2008-5353</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5354.html">CVE-2008-5354</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5359.html">CVE-2008-5359</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5360.html">CVE-2008-5360</cve>
                <bugzilla href="http://bugzilla.redhat.com/472201" id="472201">CVE-2008-5350 OpenJDK allows to list files within the user home directory (6484091)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472209" id="472209">CVE-2008-5348 OpenJDK Denial-Of-Service in kerberos authentication (6588160)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472211" id="472211">CVE-2008-5360 OpenJDK temporary files have guessable file names (6721753)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472212" id="472212">CVE-2008-5359 OpenJDK Buffer overflow in image processing (6726779)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472213" id="472213">CVE-2008-5351 OpenJDK UTF-8 decoder accepts non-shortest form sequences (4486841)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472224" id="472224">CVE-2008-5353 OpenJDK calendar object deserialization allows privilege escalation (6734167)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472228" id="472228">CVE-2008-5354 OpenJDK Privilege escalation in command line applications (6733959)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474556" id="474556">CVE-2008-2086 Java Web Start File Inclusion via System Properties Override</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474772" id="474772">CVE-2008-5339 JavaWebStart allows unauthorized network connections</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474773" id="474773">CVE-2008-5340 Java WebStart privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474789" id="474789">CVE-2008-5342 Java Web Start BasicService displays local files in the browser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474790" id="474790">CVE-2008-5343 Java WebStart allows hidden code privilege escalation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474792" id="474792">CVE-2008-5344 Java WebStart unprivileged local file and network access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474793" id="474793">CVE-2008-5345 JRE allows unauthorized file access and connections to localhost</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474794" id="474794">CVE-2008-5346 JRE allows unauthorized memory read access via a crafted ZIP file</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445004" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445005" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445012" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445010" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445008" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445009" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090445006" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445007" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090449" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0449: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0449-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0449.html" />
          <reference source="CVE" ref_id="CVE-2009-1313" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1313.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1313)

For technical details regarding this flaw, refer to the Mozilla security
advisory for Firefox 3.0.10. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.10, which corrects this issue. After installing the
update, Firefox must be restarted for the change to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-27" />
        <updated date="2009-04-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1313.html">CVE-2009-1313</cve>
                <bugzilla href="http://bugzilla.redhat.com/497447" id="497447">CVE-2009-1313 Firefox crash in nsTextFrame::ClearTextRun()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449002" comment="xulrunner is earlier than 0:1.9.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449006" comment="xulrunner-devel is earlier than 0:1.9.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449008" comment="firefox is earlier than 0:3.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090449011" comment="firefox is earlier than 0:3.0.10-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090457" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0457: libwmf security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0457-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0457.html" />
          <reference source="CVE" ref_id="CVE-2009-1364" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1364.html" />
    
    <description>libwmf is a library for reading and converting Windows Metafile Format
(WMF) vector graphics. libwmf is used by applications such as GIMP and
ImageMagick.

A pointer use-after-free flaw was found in the GD graphics library embedded
in libwmf. An attacker could create a specially-crafted WMF file that would
cause an application using libwmf to crash or, potentially, execute
arbitrary code as the user running the application when opened by a victim.
(CVE-2009-1364)

Note: This flaw is specific to the GD graphics library embedded in libwmf.
It does not affect the GD graphics library from the "gd" packages, or
applications using it.

Red Hat would like to thank Tavis Ormandy of the Google Security Team for
responsibly reporting this flaw.

All users of libwmf are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using libwmf must be restarted for the update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-30" />
        <updated date="2009-04-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1364.html">CVE-2009-1364</cve>
                <bugzilla href="http://bugzilla.redhat.com/496864" id="496864">CVE-2009-1364 libwmf: embedded gd use-after-free error</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457002" comment="libwmf is earlier than 0:0.2.8.4-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457003" comment="libwmf is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457004" comment="libwmf-devel is earlier than 0:0.2.8.4-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457005" comment="libwmf-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457007" comment="libwmf is earlier than 0:0.2.8.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457008" comment="libwmf is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457009" comment="libwmf-devel is earlier than 0:0.2.8.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457010" comment="libwmf-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090458" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0458: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0458-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0458.html" />
          <reference source="CVE" ref_id="CVE-2009-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0146.html" />
          <reference source="CVE" ref_id="CVE-2009-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0147.html" />
          <reference source="CVE" ref_id="CVE-2009-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0166.html" />
          <reference source="CVE" ref_id="CVE-2009-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0195.html" />
          <reference source="CVE" ref_id="CVE-2009-0799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0799.html" />
          <reference source="CVE" ref_id="CVE-2009-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0800.html" />
          <reference source="CVE" ref_id="CVE-2009-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1179.html" />
          <reference source="CVE" ref_id="CVE-2009-1180" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1180.html" />
          <reference source="CVE" ref_id="CVE-2009-1181" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1181.html" />
          <reference source="CVE" ref_id="CVE-2009-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1182.html" />
          <reference source="CVE" ref_id="CVE-2009-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1183.html" />
          <reference source="CVE" ref_id="CVE-2009-3606" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3606.html" />
    
    <description>GPdf is a viewer for Portable Document Format (PDF) files.

Multiple integer overflow flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in GPdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause GPdf to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF that would cause GPdf to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-30" />
        <updated date="2009-04-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0146.html">CVE-2009-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0147.html">CVE-2009-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0166.html">CVE-2009-0166</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0195.html">CVE-2009-0195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0799.html">CVE-2009-0799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0800.html">CVE-2009-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1179.html">CVE-2009-1179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1180.html">CVE-2009-1180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1181.html">CVE-2009-1181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1182.html">CVE-2009-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1183.html">CVE-2009-1183</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3606.html">CVE-2009-3606</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491864" id="491864">Multiple PDF flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090458002" comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090458003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090459" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0459: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0459-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0459.html" />
          <reference source="CVE" ref_id="CVE-2008-4307" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4307.html" />
          <reference source="CVE" ref_id="CVE-2009-0028" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0028.html" />
          <reference source="CVE" ref_id="CVE-2009-0676" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0676.html" />
          <reference source="CVE" ref_id="CVE-2009-0834" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0834.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a logic error was found in the do_setlk() function of the Linux kernel
Network File System (NFS) implementation. If a signal interrupted a lock
request, the local POSIX lock was incorrectly created. This could cause a
denial of service on the NFS server if a file descriptor was closed before
its corresponding lock request returned. (CVE-2008-4307, Important)

* a deficiency was found in the Linux kernel system call auditing
implementation on 64-bit systems. This could allow a local, unprivileged
user to circumvent a system call audit configuration, if that configuration
filtered based on the "syscall" number or arguments.
(CVE-2009-0834, Important)

* Chris Evans reported a deficiency in the Linux kernel signals
implementation. The clone() system call permits the caller to indicate the
signal it wants to receive when its child exits. When clone() is called
with the CLONE_PARENT flag, it permits the caller to clone a new child that
shares the same parent as itself, enabling the indicated signal to be sent
to the caller's parent (instead of the caller), even if the caller's parent
has different real and effective user IDs. This could lead to a denial of
service of the parent. (CVE-2009-0028, Moderate)

* the sock_getsockopt() function in the Linux kernel did not properly
initialize a data structure that can be directly returned to user-space
when the getsockopt() function is called with SO_BSDCOMPAT optname set.
This flaw could possibly lead to memory disclosure.
(CVE-2009-0676, Moderate)

Bug fixes:

* a kernel crash may have occurred for Red Hat Enterprise Linux 4.7 guests
if their guest configuration file specified "vif = [ "type=ioemu" ]". This
crash only occurred when starting guests via the "xm create" command.
(BZ#477146)

* a bug in IO-APIC NMI watchdog may have prevented Red Hat Enterprise Linux
4.7 from being installed on HP ProLiant DL580 G5 systems. Hangs during
installation and "NMI received for unknown reason [xx]" errors may have
occurred. (BZ#479184)

* a kernel deadlock on some systems when using netdump through a network
interface that uses the igb driver. (BZ#480579)

* a possible kernel hang in sys_ptrace() on the Itanium® architecture,
possibly triggered by tracing a threaded process with strace. (BZ#484904)

* the RHSA-2008:0665 errata only fixed the known problem with the LSI Logic
LSI53C1030 Ultra320 SCSI controller, for tape devices. Read commands sent
to tape devices may have received incorrect data. This issue may have led
to data corruption. This update includes a fix for all types of devices.
(BZ#487399)

* a missing memory barrier caused a race condition in the AIO subsystem
between the read_events() and aio_complete() functions. This may have
caused a thread in read_events() to sleep indefinitely, possibly causing an
application hang. (BZ#489935)

* due to a lack of synchronization in the NFS client code, modifications
to some pages (for files on an NFS mounted file system) made through a
region of memory mapped by mmap() may be lost if the NFS client invalidates
its page cache for particular files. (BZ#490119)

* a NULL pointer dereference in the megaraid_mbox driver caused a system
crash on some systems. (BZ#493420)

* the ext3_symlink() function in the ext3 file system code used an
illegal __GFP_FS allocation inside some transactions. This may have
resulted in a kernel panic and "Assertion failure" errors. (BZ#493422)

* do_machine_check() cleared all Machine Check Exception (MCE) status
registers, preventing the BIOS from using them to determine the cause of
certain panics and errors. (BZ#494915)

* a bug prevented NMI watchdog from initializing on HP ProLiant DL580 G5
systems. (BZ#497330)

This update contains backported patches to fix these issues. The system
must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-30" />
        <updated date="2009-04-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4307.html">CVE-2008-4307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0028.html">CVE-2009-0028</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0676.html">CVE-2009-0676</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0834.html">CVE-2009-0834</cve>
                <bugzilla href="http://bugzilla.redhat.com/456282" id="456282">CVE-2008-4307 Kernel BUG() in locks_remove_flock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477146" id="477146">RHEL4.7 guest will crash, if creating with only RTL8139 emulation NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479184" id="479184">RHEL 4.7: unknown NMI errors on x86_64 on DL580 G5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479932" id="479932">CVE-2009-0028 Linux kernel minor signal handling vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480579" id="480579">deadlock in igb during netdump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484904" id="484904">[RHEL4U4] strace utility can cause system to hang at sys_ptrace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486305" id="486305">CVE-2009-0676 kernel: memory disclosure in SO_BSDCOMPAT gsopt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487399" id="487399">[4.7]When SCSI READ Command is issued to tape device, the read data might not be correct for LSI 53C1030 Errata No28.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487990" id="487990">CVE-2009-0834 kernel: x86-64: syscall-audit: 32/64 syscall hole</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489935" id="489935">race in aio_complete() leads to process hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490119" id="490119">LTC41974-Pages of a memory mapped NFS file get corrupted.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493420" id="493420">NULL pointer dereference at megaraid_queue_command after a reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493422" id="493422">[RHEL4u4] Kernel panic was caused by page_symlink() when kernel has to shrink caches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497330" id="497330">Enable NMI watchdog on HP DL580 G5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459002" comment="kernel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459022" comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459004" comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459012" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459020" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459014" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459010" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459016" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459006" comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459008" comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090473" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0473: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0473-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0473.html" />
          <reference source="CVE" ref_id="CVE-2008-4307" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4307.html" />
          <reference source="CVE" ref_id="CVE-2009-0787" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0787.html" />
          <reference source="CVE" ref_id="CVE-2009-0834" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0834.html" />
          <reference source="CVE" ref_id="CVE-2009-1336" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1336.html" />
          <reference source="CVE" ref_id="CVE-2009-1337" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1337.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a logic error was found in the do_setlk() function of the Linux kernel
Network File System (NFS) implementation. If a signal interrupted a lock
request, the local POSIX lock was incorrectly created. This could cause a
denial of service on the NFS server if a file descriptor was closed before
its corresponding lock request returned. (CVE-2008-4307, Important)

* a deficiency was found in the Linux kernel system call auditing
implementation on 64-bit systems. This could allow a local, unprivileged
user to circumvent a system call audit configuration, if that configuration
filtered based on the "syscall" number or arguments.
(CVE-2009-0834, Important)

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* a flaw was found in the ecryptfs_write_metadata_to_contents() function of
the Linux kernel eCryptfs implementation. On systems with a 4096 byte
page-size, this flaw may have caused 4096 bytes of uninitialized kernel
memory to be written into the eCryptfs file headers, leading to an
information leak. Note: Encrypted files created on systems running the
vulnerable version of eCryptfs may contain leaked data in the eCryptfs file
headers. This update does not remove any leaked data. Refer to the
Knowledgebase article in the References section for further information.
(CVE-2009-0787, Moderate)

* the Linux kernel implementation of the Network File System (NFS) did not
properly initialize the file name limit in the nfs_server data structure.
This flaw could possibly lead to a denial of service on a client mounting
an NFS share. (CVE-2009-1336, Moderate)

This update also fixes the following bugs:

* the enic driver (Cisco 10G Ethernet) did not operate under
virtualization. (BZ#472474)

* network interfaces using the IBM eHEA Ethernet device driver could not be
successfully configured under low-memory conditions. (BZ#487035)

* bonding with the "arp_validate=3" option may have prevented fail overs.
(BZ#488064)

* when running under virtualization, the acpi-cpufreq module wrote "Domain
attempted WRMSR" errors to the dmesg log. (BZ#488928)

* NFS clients may have experienced deadlocks during unmount. (BZ#488929)

* the ixgbe driver double counted the number of received bytes and packets.
(BZ#489459)

* the Wacom Intuos3 Lens Cursor device did not work correctly with the
Wacom Intuos3 12x12 tablet. (BZ#489460)

* on the Itanium® architecture, nanosleep() caused commands which used it,
such as sleep and usleep, to sleep for one second more than expected.
(BZ#490434)

* a panic and corruption of slab cache data structures occurred on 64-bit
PowerPC systems when clvmd was running. (BZ#491677)

* the NONSTOP_TSC feature did not perform correctly on the Intel®
microarchitecture (Nehalem) when running in 32-bit mode. (BZ#493356)

* keyboards may not have functioned on IBM eServer System p machines after
a certain point during installation or afterward. (BZ#494293)

* using Device Mapper Multipathing with the qla2xxx driver resulted in
frequent path failures. (BZ#495635)

* if the hypervisor was booted with the dom0_max_vcpus parameter set to
less than the actual number of CPUs in the system, and the cpuspeed service
was started, the hypervisor could crash. (BZ#495931)

* using Openswan to provide an IPsec virtual private network eventually
resulted in a CPU soft lockup and a system crash. (BZ#496044)

* it was possible for posix_locks_deadlock() to enter an infinite loop
(under the BKL), causing a system hang. (BZ#496842)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-07" />
        <updated date="2009-05-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4307.html">CVE-2008-4307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0787.html">CVE-2009-0787</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0834.html">CVE-2009-0834</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1336.html">CVE-2009-1336</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1337.html">CVE-2009-1337</cve>
                <bugzilla href="http://bugzilla.redhat.com/456282" id="456282">CVE-2008-4307 Kernel BUG() in locks_remove_flock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487035" id="487035">ehea network configuration fails during boot after fsck</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487990" id="487990">CVE-2009-0834 kernel: x86-64: syscall-audit: 32/64 syscall hole</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488064" id="488064">[RHEL-5.3] ARP packets aren't received by backup slaves breaking arp_validate=3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488928" id="488928">xm dmesg printk spam -- Domain attempted WRMSR 00000000000000e8 from 00000016:3d0e9470 to 00000000:00000000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488929" id="488929">Deadlock in flush_workqueue() results in hung nfs clients</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489459" id="489459">[Intel 5.4 bug] ixgbe driver double counts RX byte count</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489460" id="489460">Wacom driver does not with with mouse/lens device on intuos3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490434" id="490434">[5.3] The nanosleep() syscall sleeps one second longer.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491254" id="491254">CVE-2009-0787 kernel: ecryptfs file header infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491677" id="491677">slab corruption with dlm and clvmd on ppc64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493356" id="493356">[Intel 5.4 FEAT] TSC keeps running in C3+[incremental patch for 5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493771" id="493771">CVE-2009-1337 kernel: exit_notify: kill the wrong capable(CAP_KILL) check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494074" id="494074">CVE-2009-1336 kernel: nfsv4 client can be crashed by stating a long filename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494293" id="494293">RHEL5-U2 Installation hangs on p-series--7029, 2078</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495635" id="495635">Frequent path failures during I/O on DM multipath devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495929" id="495929">[5.3][Xen] APERF/MPERF patch update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495931" id="495931">[5.3][Xen] dom0 panic when we use dom0_max_vcpus=2.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496044" id="496044">Running Openswan ipsec vpn server with rhel-5.3 kernel-2.6.18-128.el5 causes crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496842" id="496842">softlockups due to infinite loops in posix_locks_deadlock</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473004" comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473002" comment="kernel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473024" comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473022" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473008" comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473006" comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473018" comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473012" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473010" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473020" comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473016" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473014" comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090474" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0474: acpid security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0474-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0474.html" />
          <reference source="CVE" ref_id="CVE-2009-0798" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0798.html" />
    
    <description>acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.

Anthony de Almeida Lopes of Outpost24 AB reported a denial of service flaw
in the acpid daemon's error handling. If an attacker could exhaust the
sockets open to acpid, the daemon would enter an infinite loop, consuming
most CPU resources and preventing acpid from communicating with legitimate
processes. (CVE-2009-0798)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-07" />
        <updated date="2009-05-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0798.html">CVE-2009-0798</cve>
                <bugzilla href="http://bugzilla.redhat.com/494443" id="494443">CVE-2009-0798 acpid: too many open files DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474002" comment="acpid is earlier than 0:1.0.4-7.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474003" comment="acpid is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474005" comment="acpid is earlier than 0:1.0.2-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474006" comment="acpid is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474008" comment="acpid is earlier than 0:1.0.3-2.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474006" comment="acpid is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090476" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0476: pango security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0476-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0476.html" />
          <reference source="CVE" ref_id="CVE-2009-1194" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1194.html" />
    
    <description>Pango is a library used for the layout and rendering of internationalized
text.

Will Drewry discovered an integer overflow flaw in Pango's
pango_glyph_string_set_size() function. If an attacker is able to pass an
arbitrarily long string to Pango, it may be possible to execute arbitrary
code with the permissions of the application calling Pango. (CVE-2009-1194)

pango and evolution28-pango users are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. After
installing this update, you must restart your system or restart the X
server for the update to take effect. Note: Restarting the X server closes
all open applications and logs you out of your session.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-08" />
        <updated date="2009-05-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1194.html">CVE-2009-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/496887" id="496887">CVE-2009-1194 pango: pango_glyph_string_set_size integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476004" comment="pango-devel is earlier than 0:1.14.9-5.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476005" comment="pango-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476002" comment="pango is earlier than 0:1.14.9-5.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476003" comment="pango is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476009" comment="pango-devel is earlier than 0:1.2.5-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476010" comment="pango-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476007" comment="pango is earlier than 0:1.2.5-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476008" comment="pango is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476013" comment="pango-devel is earlier than 0:1.6.0-14.4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476010" comment="pango-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476012" comment="pango is earlier than 0:1.6.0-14.4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476008" comment="pango is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476016" comment="evolution28-pango-devel is earlier than 0:1.14.9-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476017" comment="evolution28-pango-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476014" comment="evolution28-pango is earlier than 0:1.14.9-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476015" comment="evolution28-pango is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090478" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0478: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0478-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0478.html" />
          <reference source="CVE" ref_id="CVE-2009-1492" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1492.html" />
          <reference source="CVE" ref_id="CVE-2009-1493" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1493.html" />
    
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

Two flaws were discovered in Adobe Reader's JavaScript API. A PDF file
containing malicious JavaScript instructions could cause Adobe Reader to
crash or, potentially, execute arbitrary code as the user running Adobe
Reader. (CVE-2009-1492, CVE-2009-1493)

All Adobe Reader users should install these updated packages. They contain
Adobe Reader version 8.1.5, which is not vulnerable to these issues. All
running instances of Adobe Reader must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-13" />
        <updated date="2009-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1492.html">CVE-2009-1492</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1493.html">CVE-2009-1493</cve>
                <bugzilla href="http://bugzilla.redhat.com/498322" id="498322">CVE-2009-1492, CVE-2009-1493 acroread: multiple vulnerabilities in Adobe Reader 8.1.4</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090478004" comment="acroread-plugin is earlier than 0:8.1.5-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090478002" comment="acroread is earlier than 0:8.1.5-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090479" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0479: perl-DBD-Pg security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0479-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0479.html" />
          <reference source="CVE" ref_id="CVE-2009-0663" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0663.html" />
          <reference source="CVE" ref_id="CVE-2009-1341" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1341.html" />
    
    <description>Perl DBI is a database access Application Programming Interface (API) for
the Perl language. perl-DBD-Pg allows Perl applications to access
PostgreSQL database servers.

A heap-based buffer overflow flaw was discovered in the pg_getline function
implementation. If the pg_getline or getline functions read large,
untrusted records from a database, it could cause an application using
these functions to crash or, possibly, execute arbitrary code.
(CVE-2009-0663)

Note: After installing this update, pg_getline may return more data than
specified by its second argument, as this argument will be ignored. This is
consistent with current upstream behavior. Previously, the length limit
(the second argument) was not enforced, allowing a buffer overflow.

A memory leak flaw was found in the function performing the de-quoting of
BYTEA type values acquired from a database. An attacker able to cause an
application using perl-DBD-Pg to perform a large number of SQL queries
returning BYTEA records, could cause the application to use excessive
amounts of memory or, possibly, crash. (CVE-2009-1341)

All users of perl-DBD-Pg are advised to upgrade to this updated package,
which contains backported patches to fix these issues. Applications using
perl-DBD-Pg must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-13" />
        <updated date="2009-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0663.html">CVE-2009-0663</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1341.html">CVE-2009-1341</cve>
                <bugzilla href="http://bugzilla.redhat.com/497367" id="497367">CVE-2009-0663 perl-DBD-Pg: pg_getline buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497503" id="497503">CVE-2009-1341 perl-DBD-Pg: dequote_bytea memory leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090479002" comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090479003" comment="perl-DBD-Pg is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090480" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0480: poppler security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0480.html" />
          <reference source="CVE" ref_id="CVE-2009-0146" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0146.html" />
          <reference source="CVE" ref_id="CVE-2009-0147" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0147.html" />
          <reference source="CVE" ref_id="CVE-2009-0166" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0166.html" />
          <reference source="CVE" ref_id="CVE-2009-0195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0195.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-0799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0799.html" />
          <reference source="CVE" ref_id="CVE-2009-0800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0800.html" />
          <reference source="CVE" ref_id="CVE-2009-1179" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1179.html" />
          <reference source="CVE" ref_id="CVE-2009-1180" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1180.html" />
          <reference source="CVE" ref_id="CVE-2009-1181" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1181.html" />
          <reference source="CVE" ref_id="CVE-2009-1182" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1182.html" />
          <reference source="CVE" ref_id="CVE-2009-1183" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1183.html" />
          <reference source="CVE" ref_id="CVE-2009-1187" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1187.html" />
          <reference source="CVE" ref_id="CVE-2009-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1188.html" />
          <reference source="CVE" ref_id="CVE-2009-3604" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3604.html" />
          <reference source="CVE" ref_id="CVE-2009-3606" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3606.html" />
    
    <description>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0147, CVE-2009-1179, CVE-2009-1187, CVE-2009-1188)

Multiple buffer overflow flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in poppler's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause applications that use poppler (such as Evince) to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0166,
CVE-2009-1180)

Multiple input validation flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash when opened. (CVE-2009-0799,
CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-13" />
        <updated date="2009-05-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0146.html">CVE-2009-0146</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0147.html">CVE-2009-0147</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0166.html">CVE-2009-0166</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0195.html">CVE-2009-0195</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0799.html">CVE-2009-0799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0800.html">CVE-2009-0800</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1179.html">CVE-2009-1179</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1180.html">CVE-2009-1180</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1181.html">CVE-2009-1181</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1182.html">CVE-2009-1182</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1183.html">CVE-2009-1183</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1187.html">CVE-2009-1187</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1188.html">CVE-2009-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3604.html">CVE-2009-3604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3606.html">CVE-2009-3606</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491864" id="491864">Multiple PDF flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495906" id="495906">CVE-2009-1187 poppler CairoOutputDev integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495907" id="495907">CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090480006" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480007" comment="poppler-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090480002" comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480003" comment="poppler is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090480004" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480005" comment="poppler-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090955" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0955: nfs-utils security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0955-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0955.html" />
          <reference source="CVE" ref_id="CVE-2008-1376" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1376.html" />
    
    <description>The nfs-utils package provides a daemon for the kernel NFS server and
related tools, which provides a much higher level of performance than the
traditional Linux NFS server used by most users.

A flaw was found in the nfs-utils package provided by RHBA-2008:0742. The
nfs-utils package was missing TCP wrappers support, which could result in
an administrator believing they had access restrictions enabled when they
did not. (CVE-2008-1376)

This update also includes the following bug fixes:

* the "nfsstat" command now displays correct statistics. In previous
versions, performing more than 2^31 RPC calls could cause the "nfsstat"
command to incorrectly display the number of calls as "negative". This was
because "nfsstat" printed statistics from /proc/net/rpc/* files as signed
integers; with this version of nfs-utils, "nfsstat" now reads and prints
these statistics as unsigned integers. (BZ#404831)

* imapd upcalls now support zero-length reads and perform extra bounds
checking in gssd and svcgssd. This fixes a bug in previous versions that
could cause the rpc.imapd daemon to hang when communicating with the
kernel, which would halt any ID translation services. (BZ#448710)

* tcp_wrappers supported in nfs-utils now allows proper application of
hosts access rules defined in /etc/hosts.allow and /etc/hosts.deny. (BZ#494585)

* the nfs init script did not check whether SECURE_NFS was set to "yes"
before starting, stopping, or querying rpc.svcgssd. On systems where
SECURE_NFS was not set to "yes", the nfs init script could not start the
rpc.svcgssd daemon at the "service nfs start" command because the rpcsvcssd
init script would check the status of SECURE_NFS before starting the
daemon. However, at the "service nfs stop" or "service nfs restart"
commands, nfs init script would attempt to stop rpc.svcgssd and then report
a failure because the daemon was not running in the first place. These
error messages may have misled end-users into believing that there was a
genuine problem with their NFS configuration. This version of nfs-utils
contains a fix backported from Red Hat Enterprise Linux 5. nfs-utils now
checks the status of SECURE_NFS before the nfs init script attempts to
start, query or stop rpc.svcgssd and therefore, the irrelevant error
messages seen previously will not appear. (BZ#470423)

* the nfs init script is now fully compliant with Linux Standard Base Core
specifications. This update fixes a bug that prevented "/etc/init.d/nfs
start" from exiting properly if NFS was already running. (BZ#474570)

* /var/lib/nfs/statd/sm is now created with the proper user and group
whenever rpc.statd is called. In previous versions, some thread stack
conditions could incorrectly prevent rpc.statd from creating the
/var/lib/nfs/statd/sm file, which could cause "service nfslock start" to
fail. (BZ#479376)

All users of nfs-utils should upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1376.html">CVE-2008-1376</cve>
                <bugzilla href="http://bugzilla.redhat.com/404831" id="404831">"nfsstat -s" shows negative value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440114" id="440114">CVE-2008-1376 nfs-utils: missing tcp_wrappers support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461043" id="461043">lockd not using settings in sysconfig/nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474570" id="474570">Incorrect exit codes from nfs init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479376" id="479376">statd fails to create SM_DIR</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494585" id="494585">libwrap - Nor ip, nor hostname work,, only when used ALL expression in hosts.deny access is denied</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090955002" comment="nfs-utils is earlier than 0:1.0.6-93.EL4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090955003" comment="nfs-utils is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090981" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:0981: util-linux security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:0981-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0981.html" />
          <reference source="CVE" ref_id="CVE-2008-1926" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1926.html" />
    
    <description>The util-linux package contains a collection of basic system utilities,
such as fdisk and mount.

A log injection attack was found in util-linux when logging log in attempts
via the audit subsystem of the Linux kernel. A remote attacker could use
this flaw to modify certain parts of logged events, possibly hiding their
activities on a system. (CVE-2008-1926)

This updated package also fixes the following bugs:

* partitions created by VMware ESX™ were not included in the list of
recognized file systems used by fdisk. Consequently, if VMware ESX was
installed, "fdisk -l" returned "Unknown" for these partitions. With this
update, information regarding the VMKcore and VMFS partitions has been
added to the file systems list. On systems running VMware ESX, "fdisk -l"
now lists information about these partitions as expected. (BZ#447264)

* if a username was not set, the login command would fail with a
Segmentation fault. With this update, login lets the audit system handle
NULL usernames (it sends an AUDIT_USER_LOGIN message to the audit system in
the event there is no username set). (BZ#456213)

* the nfs(5) man page listed version 2 as the default. This is incorrect:
unless otherwise specified, the NFS client uses NFS version 3. The man page
has been corrected. (BZ#458539)

* in certain situations, backgrounded NFS mounts died shortly after being
backgrounded when the mount command was executed by the initlog command,
which, for example, would occur when running an init script, such as
running the "service netfs start" command. In these situations, running the
"ps -ef" command showed backgrounded NFS mounts disappearing shortly after
being backgrounded. In this updated package, backgrounded mount processes
detach from the controlling terminal, which resolves this issue.
(BZ#461488)

* if a new partition's starting cylinder was beyond one terabyte, fdisk
could not create the partition. This has been fixed. (BZ#471372)

* in rare cases "mount -a" ignored fstab order and tried to re-mount file
systems on mpath devices. With this update, mount honors fstab order even
in the rare cases reported. (BZ#472186)

* the "mount --move" command moved a file system's mount point as expected
(for example, /proc/mounts showed the changed mount point as expected) but
did not update /etc/mtab properly. With this update, the "mount --move"
command gathers all necessary information about the old mount point, copies
it to the new mount point and then deletes the old point, ensuring
/etc/mtab is updated properly. (BZ#485004)

Util-linux users are advised to upgrade to this updated package, which
addresses this vulnerability and resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1926.html">CVE-2008-1926</cve>
                <bugzilla href="http://bugzilla.redhat.com/443925" id="443925">CVE-2008-1926 util-linux: audit log injection via login</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447264" id="447264">RHEL4: VMware fdisk partitions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456213" id="456213">RHEL4: login segfaults on EOF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456379" id="456379">RHEL4: audit log injection attack via login</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458539" id="458539">man nfs : wrong information about nfs version used</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461488" id="461488">Backgrounded NFS mounts dies soon after "service netfs start" command is issued</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471372" id="471372">RHEL4: fdisk cannot create partition with starting beyond 1 TB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472186" id="472186">mount -a has problems with duplicate labels in a mpath setup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485004" id="485004">Move mount doesn't correctly update mtab</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090981002" comment="util-linux is earlier than 0:2.12a-24.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090981003" comment="util-linux is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091024" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1024: Red Hat Enterprise Linux 4.8 kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1024-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1024.html" />
          <reference source="CVE" ref_id="CVE-2009-1336" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1336.html" />
          <reference source="CVE" ref_id="CVE-2009-1337" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1337.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security Fixes:

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* the Linux kernel implementation of the Network File System (NFS) did not
properly initialize the file name limit in the nfs_server data structure.
This flaw could possibly lead to a denial of service on a client mounting
an NFS share. (CVE-2009-1336, Moderate)

Bug Fixes and Enhancements:

Kernel Feature Support:

* added a new allowable value to "/proc/sys/kernel/wake_balance" to allow
the scheduler to run the thread on any available CPU rather than scheduling
it on the optimal CPU.
* added "max_writeback_pages" tunable parameter to /proc/sys/vm/ to allow
the maximum number of modified pages kupdate writes to disk, per iteration
per run.
* added "swap_token_timeout" tunable parameter to /proc/sys/vm/ to provide
a valid hold time for the swap out protection token.
* added diskdump support to sata_svw driver.
* limited physical memory to 64GB for 32-bit kernels running on systems
with more than 64GB of physical memory to prevent boot failures.
* improved reliability of autofs.
* added support for 'rdattr_error' in NFSv4 readdir requests.
* fixed various short packet handling issues for NFSv4 readdir and sunrpc.
* fixed several CIFS bugs.

Networking and IPv6 Enablement:

* added router solicitation support.
* enforced sg requires tx csum in ethtool.

Platform Support:

x86, AMD64, Intel 64, IBM System z

* added support for a new Intel chipset.
* added initialization vendor info in boot_cpu_data.
* added support for N_Port ID Virtualization (NPIV) for IBM System z guests
using zFCP.
* added HDMI support for some AMD and ATI chipsets.
* updated HDA driver in ALSA to latest upstream as of 2008-07-22.
* added support for affected_cpus for cpufreq.
* removed polling timer from i8042.
* fixed PM-Timer when using the ASUS A8V Deluxe motherboard.
* backported usbfs_mutex in usbfs.

64-bit PowerPC:

* updated eHEA driver from version 0078-04 to 0078-08.
* updated logging of checksum errors in the eHEA driver.

Network Driver Updates:

* updated forcedeth driver to latest upstream version 0.61.
* fixed various e1000 issues when using Intel ESB2 hardware.
* updated e1000e driver to upstream version 0.3.3.3-k6.
* updated igb to upstream version 1.2.45-k2.
* updated tg3 to upstream version 3.96.
* updated ixgbe to upstream version 1.3.18-k4.
* updated bnx2 to upstream version 1.7.9.
* updated bnx2x to upstream version 1.45.23.
* fixed bugs and added enhancements for the NetXen NX2031 and NX3031
products.
* updated Realtek r8169 driver to support newer network chipsets. All
variants of RTL810x/RTL8168(9) are now supported.

Storage Driver Updates:

* fixed various SCSI issues. Also, the SCSI sd driver now calls the
revalidate_disk wrapper.
* fixed a dmraid reduced I/O delay bug in certain configurations.
* removed quirk aac_quirk_scsi_32 for some aacraid controllers.
* updated FCP driver on IBM System z systems with support for
point-to-point connections.
* updated lpfc to version 8.0.16.46.
* updated megaraid_sas to version 4.01-RH1.
* updated MPT Fusion driver to version 3.12.29.00rh.
* updated qla2xxx firmware to 4.06.01 for 4GB/s and 8GB/s adapters.
* updated qla2xxx driver to version 8.02.09.00.04.08-d.
* fixed sata_nv in libsata to disable ADMA mode by default.

Miscellaneous Updates:

* upgraded OpenFabrics Alliance Enterprise Distribution (OFED) to version
1.4.
* added driver support and fixes for various Wacom tablets.

Users should install this update, which resolves these issues and adds
these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1336.html">CVE-2009-1336</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1337.html">CVE-2009-1337</cve>
                <bugzilla href="http://bugzilla.redhat.com/161590" id="161590">sr_get_mcn: check for kmalloc failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/161594" id="161594">drivers/scsi/sg.c: fix check after use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/169129" id="169129">remove tape during error handling -> "illegal state transition"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175189" id="175189">Debug: sleeping function called from invalid context at include/linux/rwsem.h:43</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/175830" id="175830">dm-snap.c: Data read from snapshot may be corrupt if origin is being written to simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/182687" id="182687">lm_sensors fails with piix4_smbus errors on ServerWorks Grand Champion SL/w83781d</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/183651" id="183651">sd data corrupter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/185585" id="185585">Hangs when registering modules to handle ioctls in kernel compatibility mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191764" id="191764">[PATCH] Don't match tcp/udp source/destination port for IP fragments</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191767" id="191767">[PATCH] NET: Ensure device name passed to SO_BINDTODEVICE is NULL terminated.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191770" id="191770">[PATCH] Netfilter ip_queue: Fix wrong skb->len == nlmsg_len assumption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191777" id="191777">[PATCH] Fix deadlock in br_stp_disable_bridge</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/191797" id="191797">[PATCH] Fix extra dst release when ip_options_echo fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/203235" id="203235">PMTimer doesn't get detected in an Asus A8V Deluxe motherboard</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243067" id="243067">Kernel panic using USB serial I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248666" id="248666">Serious problems during the diskdump, can cause the machine to hang and not reboot.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249775" id="249775">Request to backport zFCP NPIV support to RHEL 4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249867" id="249867">Kernel can BUG() in low memory conditions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/253754" id="253754">use after free in nlm subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/294821" id="294821">RHEL4.5: PM Timer appears in top-level make menuconfig</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/298811" id="298811">pci_alloc_consistent() for 64k on 16gig machine -> return value is not multiple of 64k</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/329201" id="329201">scsi hot swapp mechanism not working with SATA HDD under RHEL4U5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/334411" id="334411">Watchdog timeout e1000 (7.3.20-k2-NAPI)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/367661" id="367661">Getting Cpu stuck messages on boot up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430997" id="430997">tx checksum offload settings reported incorrectly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432364" id="432364">e1000e: Wakeup-on-Lan does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432393" id="432393">memory leak on size-8192 buckets with NFSV4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432881" id="432881">kernel: NFS: v4 server returned a bad sequence-id error!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437410" id="437410">ip tunnel can't be bound to another device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437555" id="437555">via-rhine may lose link</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437674" id="437674">Kernel Panic in tcp_retransmit_skb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437881" id="437881">ptrace: orig_rax 0x00000000ffffffff not recognized as -1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437921" id="437921">[PATCH] NFSv3: mode of the symlink can be update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439043" id="439043">Swap Token issue with RHEL4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439431" id="439431">include patch to add FATTR4_RDATTR_ERROR to readdir calls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439548" id="439548">A deadlock can occur between mmap/munmap and journaling(ext3).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439920" id="439920">entropy generation in bnx2 driver not consistent with other network drivers on RHEL4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439921" id="439921">align per-cpu section to configured cache bytes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440467" id="440467">ethttool -S on r8169 version 2.2LK hangs when interface is down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441707" id="441707">ADMA problems with sata_nv</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441794" id="441794">intermittant mount failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442579" id="442579">Backport fix for possible data corruption in mark_buffer_dirty on SMP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443044" id="443044">fix setuid/setgid clearing by knfsd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443655" id="443655">Clean up handling of short readdir packets in NFS client</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445054" id="445054">8250 serial port lock recursion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445412" id="445412">clean up CIFS build warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445795" id="445795">/proc filesystem in RHEL4 doesn't follow usual unix filesystem conventions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446083" id="446083">Ensure that 'noac' and/or 'actimeo=0' turn off attribute caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446396" id="446396">crm #1790828 Kernel 2.6.9-67.ELsmp panics in nfs4_free_client</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447397" id="447397">CIFS: slab error in kmem_cache_destroy(): cache `cifs_request': Can't free all objects</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447401" id="447401">CIFS VFS: Send error in FindClose = -9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447413" id="447413">CIFS: clear DFS bit in header_assemble</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447569" id="447569">mounting CIFS subshare doesn't autoconvert prepath delimiters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447741" id="447741">JBD: Fix typo that could result in filesystem corruption.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448076" id="448076">memory corruption due to portmap call succeeding after parent rpc_clnt has been freed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448603" id="448603">holding files under /proc/net open no longer adds to module refcount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448777" id="448777">Backport FCP point-to-point to RHEL 4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450953" id="450953">el4u6 xenU guest kernel lockup due to mm_unpinned_lock and runqueue spinlock deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451819" id="451819">process hangs in async direct IO / possible race between dio_bio_end_aio() and dio_await_one() ?</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451827" id="451827">[rhel 4.6] System Time drifts forward with TSC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452287" id="452287">[Intel 4.8 FEAT] e1000e driver update to latest upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452289" id="452289">[Intel 4.8 FEAT] igb driver update to latest upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452292" id="452292">[Intel 4.8 FEAT] ixgbe driver update to latest upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452390" id="452390">PATH and EXECVE audit records contain bogus newlines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452706" id="452706">kernel BUG at kernel/signal.c:369! (attempt to free tsk->signal twice)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452846" id="452846">FEAT: RHEL 4.8 HDA ALSA driver update from mainstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453053" id="453053">RHSA-2008:0508 linux-2.6.9-x86_64-copy_user-zero-tail.patch broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453171" id="453171">kernel: usbhid: probe of 3-1:1.0 failed with error -5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453359" id="453359">page keeps non uptodate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453507" id="453507">kernel panic with  kernel version 2.6.9-67.0.20.EL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454050" id="454050">Fail to build kernel when enable CONFIG_ACPI_DEBUG in .config</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454417" id="454417">Inconsistent documentation regarding pci_alloc_consistent</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454793" id="454793">document divider= option in kernel docs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454838" id="454838">LTC:4.8:201714:Update the ehea driver to sync with mainline kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454872" id="454872">[NetApp 4.8 bug] online resize of filesystem does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455253" id="455253">[4.7] /proc/acpi/dsdt: No such device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455756" id="455756">[RHEL4/Xen]: Allow attach of > 16 xvd devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455843" id="455843">Kernel panic at hcd_pci_release+16</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455917" id="455917">fattr structs being used uninitialized in nfs3_proc_getacl and nfs3_proc_setacls</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456051" id="456051">kernel: fix array out of bounds when mounting with selinux options [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456078" id="456078">Timeouts in wait_drive_not_busy with TEAC DV-W28ECW and similar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456425" id="456425">Crash dump fails on IA64 with block_order set to 10</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456438" id="456438">[RHEL4.7 Beta] Wake on LAN function does not operate with LAN card which uses igb driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456653" id="456653">Crash due to incorrect inet{,6} device initialization order</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456664" id="456664">Kernel panic when unloading ip conntrack modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456686" id="456686">race in aio_complete() leads to process hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456911" id="456911">RHEL4 scheduler optimizations for financial applications</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457009" id="457009">ipv6: use timer pending to fix bridge reference count problem [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457015" id="457015">pppoe: Check packet length on all receive paths [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457020" id="457020">pppoe: Unshare skb before anything else [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457028" id="457028">ide-cd: fix oops when using growisofs [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457310" id="457310">RTL8101E with driver r8169 does not work on 1000 network</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457409" id="457409">[RHEL4.6] x86_64 race condition at shutdown/panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457552" id="457552">aac_fib_send failed with status 8195</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458022" id="458022">kernel: random32: seeding improvement [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458805" id="458805">missing infiniband kernel headers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458863" id="458863">Backport NetXen nic driver from upstream kernel to RHEL4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458955" id="458955">Badness in __writeback_single_inode at fs/fs-writeback.c:248</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459063" id="459063">pppoe: Fix skb_unshare_check call position [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459222" id="459222">RHEL4.8: Patch to support new HDMI Audio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459644" id="459644">[RHEL4] nmi watchdog: include fix for Pentium 4 D processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460083" id="460083">Kernel part of AutoFS still having issues with expiration of submount maps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460106" id="460106">regression, rhel4.7+, on the try to read /proc/self/mem getting improper return value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460859" id="460859">kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-4.8]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460874" id="460874">lost packets when live migrating (RHEL4 XEN)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461005" id="461005">CIFS option forcedirectio fails to allow the appending of text to files.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461014" id="461014">netdump fails when bnx2 has remote copper PHY - Badness in local_bh_enable at kernel/softirq.c:141</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461085" id="461085">lockd: return NLM_LCK_DENIED_GRACE_PERIOD after long periods</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461246" id="461246">RHEL4 64 bit skips all pids with bit 15 set (32768-65535, 98304-131071 etc)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462277" id="462277">find using an automounted directory results in 'No such file or directory'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462278" id="462278">do_mount_indirect: indirect trigger not valid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462459" id="462459">Update CIFS for RHEL4.8</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463897" id="463897">[RHEL4 PV-on-HVM]: Crash in xen-vbd when trying to attach disks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464676" id="464676">virtual ethernet device stops working on reception of duplicate backend state change signals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465360" id="465360">openib creates multiple /proc/net/sdp files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465366" id="465366">add multi-core support to cpufreq driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465487" id="465487">Fix compile warnings caused by adding roundup() to kernel.h</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465914" id="465914">rhel4 PV guest installations busted on rhel 5.3 i386 intel dom0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466127" id="466127">dasd: fix loop in request expiration handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467442" id="467442">Concurrent CIFS mount/umount processes to same windows machine, different shares hangs umount processes or crashes kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467669" id="467669">kernel panic related to autofs4_catatonic_mode when stopping autofs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467714" id="467714">Kernel BUG at include/linux/module.h:397</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467829" id="467829">md: pass down BIO_RW_SYNC in raid{1,10}' applied to RHEL4 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468890" id="468890">BUG() call in net/core/skbuff.c in function ___pksb_trim()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471560" id="471560">[4.7.z] Unable to Unload "ohci-hcd " And to Reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472005" id="472005">[Stratus 4.8 bug REVERT] panic reading /proc/bus/input/devices during input device removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472557" id="472557">futex missreporting ETIMEDOUT instead of EINVAL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472568" id="472568">CRM #1862478 xen guest installation panics when installing 100th guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472572" id="472572">RHEL4.7 guest will crash, if creating with only RTL8139 emulation NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473258" id="473258">[4.7] ethtool operation to the slave device of bonding makes the system hang up.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474055" id="474055">[RHEL-4] wacomexpresskeys: fix Graphire support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474479" id="474479">RHEL4.8 kernel crashed in net_rx_action() on IA64 machine in RHTS connectathon test</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474667" id="474667">Need to build xen-platform-pci as a module and not into the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475715" id="475715">[autofs4] Incorrect "active offset mount" messages in syslog</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475849" id="475849">[RHEL 4.7 Xen]: Guest hang on FV save/restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476461" id="476461">panic in kcopyd during snapshot I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476704" id="476704">[QLogic 4.8 bug] qla2xxx - Properly support programmable devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476726" id="476726">[nfs] actimeo=0 not enforced during ftruncate operations, resulting in database crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477202" id="477202">oops in net_rx_action on double free of dev->poll_list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477280" id="477280">[QLogic 4.8 bug] qla4xxx - Driver Update Patches - bugs, cleanups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477635" id="477635">If diskdump fails, panic information should be displayed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477945" id="477945">Kernel Panic with Bnx2 - Badness in local_bh_enable at kernel/softirq.c:141</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478687" id="478687">LTC:4.8:200770:Include Open Fabric Enterprise Distribution</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478798" id="478798">fix scsi device cleanup when sysfs addition fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479094" id="479094">[QLogic 4.8 bug] qla2xxx - Updates from standard and upstream drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479728" id="479728">NFS: unable to unmount file system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479764" id="479764">Leap second message can hang the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479845" id="479845">Kernel maintainer's bz for committing some maintenance patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479862" id="479862">[QLogic 4.8 bug] qla4xxx - Correct version number</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479910" id="479910">Kernel Panic on AMD-K6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480137" id="480137">Improve udp port randomization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480158" id="480158">RHEL 4.8 mpt driver fails to bring up device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480666" id="480666">[EMULEX 4.8 bug] scsi messages correlate with silent data corruption, but no i/o errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481207" id="481207">netdump generates incomplete vmcore logs with Broadcom BCM5754</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482822" id="482822">Intel E1000 doesn't work on NVIDIA MCP51 motherboards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483535" id="483535">RHEL4 kvm virtio: kernel driver updates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484261" id="484261">cifs mounted home directory breaks ssh security checks on authorized_keys file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484319" id="484319">Random crashing in dm snapshots because of a race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484376" id="484376">netdump is broken on igb and ixgbe devices in recent update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484667" id="484667">Dropping packets in bnx2 since 1.7.9 bnx2 version</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485092" id="485092">[Qlogic 4.8 bug] qla4xxx: properly support the Async Msg PDU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485421" id="485421">Kernel panic when running xen-vnif enabled FV guest image on KVM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488018" id="488018">NMI appears to be stuck (460) - NMI received for unknown reason 21</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489300" id="489300">fix dst cache leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489768" id="489768">[RHEL4u4] Kernel panic was caused by page_symlink() when kernel has to shrink caches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490021" id="490021">Creation of mirrored logical volume with VG extent-size of 1K fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490744" id="490744">UNDERRUN and TIMEOUT status with qla2xxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491154" id="491154">divider option does not work with TSC clocksource</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491784" id="491784">[QLogic 4.8 bug] qla2xxx - fixes for flash, loop resets and HBA traversal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492156" id="492156">[QLogic 4.8 bug] qla2xxx - firmware update for blade servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493771" id="493771">CVE-2009-1337 kernel: exit_notify: kill the wrong capable(CAP_KILL) check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494074" id="494074">CVE-2009-1336 kernel: nfsv4 client can be crashed by stating a long filename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495673" id="495673">kernel dm crypt: memory corruption when invalid mapping parameters provided</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024002" comment="kernel is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024022" comment="kernel-doc is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024004" comment="kernel-devel is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024008" comment="kernel-smp-devel is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024018" comment="kernel-hugemem is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024012" comment="kernel-largesmp is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024006" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024014" comment="kernel-xenU is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024010" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091024016" comment="kernel-smp is earlier than 0:2.6.9-89.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091036" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1036: ipsec-tools security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1036-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1036.html" />
          <reference source="CVE" ref_id="CVE-2009-1574" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1574.html" />
          <reference source="CVE" ref_id="CVE-2009-1632" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1632.html" />
    
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the Linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon. An
unauthenticated, remote attacker could trigger a NULL pointer dereference
that could cause the racoon daemon to crash. (CVE-2009-1574)

Multiple memory leak flaws were found in the ipsec-tools racoon daemon. If
a remote attacker is able to make multiple connection attempts to the
racoon daemon, it was possible to cause the racoon daemon to consume all
available memory. (CVE-2009-1632)

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches to correct these issues. Users must restart the racoon
daemon for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1574.html">CVE-2009-1574</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1632.html">CVE-2009-1632</cve>
                <bugzilla href="http://bugzilla.redhat.com/497990" id="497990">CVE-2009-1574 ipsec-tools: racoon NULL dereference in fragmentation code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500886" id="500886">CVE-2009-1632 ipsec-tools: multiple memory leaks fixed in 0.7.2</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091036002" comment="ipsec-tools is earlier than 0:0.6.5-13.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091036003" comment="ipsec-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091038" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1038: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1038-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1038.html" />
          <reference source="CVE" ref_id="CVE-2009-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1093.html" />
          <reference source="CVE" ref_id="CVE-2009-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1094.html" />
          <reference source="CVE" ref_id="CVE-2009-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1095.html" />
          <reference source="CVE" ref_id="CVE-2009-1096" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1096.html" />
          <reference source="CVE" ref_id="CVE-2009-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1097.html" />
          <reference source="CVE" ref_id="CVE-2009-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1098.html" />
          <reference source="CVE" ref_id="CVE-2009-1099" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1099.html" />
          <reference source="CVE" ref_id="CVE-2009-1100" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1100.html" />
          <reference source="CVE" ref_id="CVE-2009-1101" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1101.html" />
          <reference source="CVE" ref_id="CVE-2009-1103" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1103.html" />
          <reference source="CVE" ref_id="CVE-2009-1104" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1104.html" />
          <reference source="CVE" ref_id="CVE-2009-1105" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1105.html" />
          <reference source="CVE" ref_id="CVE-2009-1106" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1106.html" />
          <reference source="CVE" ref_id="CVE-2009-1107" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1107.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100,
CVE-2009-1101, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106,
CVE-2009-1107)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR9-SSU Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1093.html">CVE-2009-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1094.html">CVE-2009-1094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1095.html">CVE-2009-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1096.html">CVE-2009-1096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1097.html">CVE-2009-1097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1098.html">CVE-2009-1098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1099.html">CVE-2009-1099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1100.html">CVE-2009-1100</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1101.html">CVE-2009-1101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1103.html">CVE-2009-1103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1104.html">CVE-2009-1104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1105.html">CVE-2009-1105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1106.html">CVE-2009-1106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1107.html">CVE-2009-1107</cve>
                <bugzilla href="http://bugzilla.redhat.com/490166" id="490166">CVE-2009-1101 OpenJDK JAX-WS service endpoint remote Denial-of-Service (6630639)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490167" id="490167">CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service (6717680)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490168" id="490168">CVE-2009-1094 OpenJDK  LDAP client remote code execution (6737315)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490169" id="490169">CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490174" id="490174">CVE-2009-1097 OpenJDK PNG processing buffer overflow vulnerability (6804996)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490178" id="490178">CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability (6804998)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492302" id="492302">CVE-2009-1099 OpenJDK: Type1 font processing buffer overflow vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492305" id="492305">CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492306" id="492306">CVE-2009-1103 OpenJDK: Files disclosure, arbitrary code execution via "deserializing applets" (6646860)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492308" id="492308">CVE-2009-1104 OpenJDK: Intended access restrictions bypass via LiveConnect (6724331)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492309" id="492309">CVE-2009-1105 OpenJDK: Possibility of trusted applet run in older, vulnerable version of JRE (6706490)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492310" id="492310">CVE-2009-1106 OpenJDK: Improper parsing of crossdomain.xml files (intended access restriction bypass) (6798948)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492312" id="492312">CVE-2009-1107 OpenJDK: Signed applet remote misuse possibility (6782871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038004" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038008" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016009" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038016" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038014" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016017" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038006" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038010" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016011" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091038012" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.9-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016013" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091039" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1039: ntp security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1039.html" />
          <reference source="CVE" ref_id="CVE-2009-0159" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0159.html" />
          <reference source="CVE" ref_id="CVE-2009-1252" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1252.html" />
    
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A buffer overflow flaw was discovered in the ntpd daemon's NTPv4
authentication code. If ntpd was configured to use public key cryptography
for NTP packet authentication, a remote attacker could use this flaw to
send a specially-crafted request packet that could crash ntpd.
(CVE-2009-1252)

Note: NTP authentication is not enabled by default.

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0159.html">CVE-2009-0159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1252.html">CVE-2009-1252</cve>
                <bugzilla href="http://bugzilla.redhat.com/490617" id="490617">CVE-2009-0159 ntp: buffer overflow in ntpq</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499694" id="499694">CVE-2009-1252 ntp: remote arbitrary code execution vulnerability if autokeys is enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091039002" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046003" comment="ntp is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091040" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1040: ntp security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1040-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1040.html" />
          <reference source="CVE" ref_id="CVE-2009-0159" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0159.html" />
          <reference source="CVE" ref_id="CVE-2009-1252" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1252.html" />
    
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A buffer overflow flaw was discovered in the ntpd daemon's NTPv4
authentication code. If ntpd was configured to use public key cryptography
for NTP packet authentication, a remote attacker could use this flaw to
send a specially-crafted request packet that could crash ntpd or,
potentially, execute arbitrary code with the privileges of the "ntp" user.
(CVE-2009-1252)

Note: NTP authentication is not enabled by default.

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq or, potentially, execute arbitrary code with
the privileges of the user running the ntpq command. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0159.html">CVE-2009-0159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1252.html">CVE-2009-1252</cve>
                <bugzilla href="http://bugzilla.redhat.com/490617" id="490617">CVE-2009-0159 ntp: buffer overflow in ntpq</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499694" id="499694">CVE-2009-1252 ntp: remote arbitrary code execution vulnerability if autokeys is enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091040002" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046006" comment="ntp is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091059" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1059: pidgin security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1059-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1059.html" />
          <reference source="CVE" ref_id="CVE-2009-1373" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1373.html" />
          <reference source="CVE" ref_id="CVE-2009-1376" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1376.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A buffer overflow flaw was found in the way Pidgin initiates file transfers
when using the Extensible Messaging and Presence Protocol (XMPP). If a
Pidgin client initiates a file transfer, and the remote target sends a
malformed response, it could cause Pidgin to crash or, potentially, execute
arbitrary code with the permissions of the user running Pidgin. This flaw
only affects accounts using XMPP, such as Jabber and Google Talk.
(CVE-2009-1373)

It was discovered that on 32-bit platforms, the Red Hat Security Advisory
RHSA-2008:0584 provided an incomplete fix for the integer overflow flaw
affecting Pidgin's MSN protocol handler. If a Pidgin client receives a
specially-crafted MSN message, it may be possible to execute arbitrary code
with the permissions of the user running Pidgin. (CVE-2009-1376)

Note: By default, when using an MSN account, only users on your buddy list
can send you messages. This prevents arbitrary MSN users from exploiting
this flaw.

All Pidgin users should upgrade to this update package, which contains
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1373.html">CVE-2009-1373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1376.html">CVE-2009-1376</cve>
                <bugzilla href="http://bugzilla.redhat.com/500488" id="500488">CVE-2009-1373 pidgin file transfer buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500493" id="500493">CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059002" comment="pidgin is earlier than 0:1.5.1-3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091060" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1060: pidgin security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1060-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1060.html" />
          <reference source="CVE" ref_id="CVE-2009-1373" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1373.html" />
          <reference source="CVE" ref_id="CVE-2009-1374" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1374.html" />
          <reference source="CVE" ref_id="CVE-2009-1375" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1375.html" />
          <reference source="CVE" ref_id="CVE-2009-1376" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1376.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A buffer overflow flaw was found in the way Pidgin initiates file transfers
when using the Extensible Messaging and Presence Protocol (XMPP). If a
Pidgin client initiates a file transfer, and the remote target sends a
malformed response, it could cause Pidgin to crash or, potentially, execute
arbitrary code with the permissions of the user running Pidgin. This flaw
only affects accounts using XMPP, such as Jabber and Google Talk.
(CVE-2009-1373)

A denial of service flaw was found in Pidgin's QQ protocol decryption
handler. When the QQ protocol decrypts packet information, heap data can be
overwritten, possibly causing Pidgin to crash. (CVE-2009-1374)

A flaw was found in the way Pidgin's PurpleCircBuffer object is expanded.
If the buffer is full when more data arrives, the data stored in this
buffer becomes corrupted. This corrupted data could result in confusing or
misleading data being presented to the user, or possibly crash Pidgin.
(CVE-2009-1375)

It was discovered that on 32-bit platforms, the Red Hat Security Advisory
RHSA-2008:0584 provided an incomplete fix for the integer overflow flaw
affecting Pidgin's MSN protocol handler. If a Pidgin client receives a
specially-crafted MSN message, it may be possible to execute arbitrary code
with the permissions of the user running Pidgin. (CVE-2009-1376)

Note: By default, when using an MSN account, only users on your buddy list
can send you messages. This prevents arbitrary MSN users from exploiting
this flaw.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1373.html">CVE-2009-1373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1374.html">CVE-2009-1374</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1375.html">CVE-2009-1375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1376.html">CVE-2009-1376</cve>
                <bugzilla href="http://bugzilla.redhat.com/500488" id="500488">CVE-2009-1373 pidgin file transfer buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500490" id="500490">CVE-2009-1374 pidgin DoS when decrypting qq packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500491" id="500491">CVE-2009-1375 pidgin PurpleCircBuffer corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500493" id="500493">CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060016" comment="finch is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060017" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060010" comment="libpurple-perl is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060011" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060008" comment="libpurple is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060009" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060002" comment="pidgin is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060018" comment="pidgin-devel is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060012" comment="pidgin-perl is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060013" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060006" comment="finch-devel is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060007" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060004" comment="libpurple-devel is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060005" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060014" comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060015" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060037" comment="libpurple-perl is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060038" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060031" comment="finch is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060032" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060029" comment="libpurple is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060030" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060021" comment="pidgin is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060035" comment="pidgin-devel is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060036" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060033" comment="finch-devel is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060034" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060027" comment="pidgin-perl is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060028" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060025" comment="libpurple-devel is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060026" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060023" comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060024" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091061" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1061: freetype security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1061.html" />
          <reference source="CVE" ref_id="CVE-2009-0946" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0946.html" />
    
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.

Tavis Ormandy of the Google Security Team discovered several integer
overflow flaws in the FreeType 2 font engine. If a user loaded a
carefully-crafted font file with an application linked against FreeType 2,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2009-0946)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0946.html">CVE-2009-0946</cve>
                <bugzilla href="http://bugzilla.redhat.com/491384" id="491384">CVE-2009-0946 freetype: multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091061002" comment="freetype is earlier than 0:2.2.1-21.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091061003" comment="freetype is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091061006" comment="freetype-demos is earlier than 0:2.2.1-21.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091061007" comment="freetype-demos is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091061004" comment="freetype-devel is earlier than 0:2.2.1-21.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091061005" comment="freetype-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091066" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1066: squirrelmail security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1066.html" />
          <reference source="CVE" ref_id="CVE-2009-1578" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1578.html" />
          <reference source="CVE" ref_id="CVE-2009-1579" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1579.html" />
          <reference source="CVE" ref_id="CVE-2009-1581" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1581.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP.

A server-side code injection flaw was found in the SquirrelMail
"map_yp_alias" function. If SquirrelMail was configured to retrieve a
user's IMAP server address from a Network Information Service (NIS) server
via the "map_yp_alias" function, an unauthenticated, remote attacker using
a specially-crafted username could use this flaw to execute arbitrary code
with the privileges of the web server. (CVE-2009-1579)

Multiple cross-site scripting (XSS) flaws were found in SquirrelMail. An
attacker could construct a carefully crafted URL, which once visited by an 
unsuspecting user, could cause the user's web browser to execute malicious
script in the context of the visited SquirrelMail web page. (CVE-2009-1578)

It was discovered that SquirrelMail did not properly sanitize Cascading
Style Sheets (CSS) directives used in HTML mail. A remote attacker could
send a specially-crafted email that could place mail content above
SquirrelMail's controls, possibly allowing phishing and cross-site
scripting attacks. (CVE-2009-1581)

Users of squirrelmail should upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-26" />
        <updated date="2009-05-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1578.html">CVE-2009-1578</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1579.html">CVE-2009-1579</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1581.html">CVE-2009-1581</cve>
                <bugzilla href="http://bugzilla.redhat.com/500356" id="500356">CVE-2009-1581 SquirrelMail: CSS positioning vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500360" id="500360">CVE-2009-1579 SquirrelMail: Server-side code injection in map_yp_alias username map</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500363" id="500363">CVE-2009-1578 SquirrelMail: Multiple cross site scripting issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091066002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091066005" comment="squirrelmail is earlier than 0:1.4.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091066008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091075" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1075: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1075-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1075.html" />
          <reference source="CVE" ref_id="CVE-2008-1678" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1678.html" />
          <reference source="CVE" ref_id="CVE-2009-1195" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1195.html" />
    
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the handling of compression structures between mod_ssl
and OpenSSL. If too many connections were opened in a short period of time,
all system memory and swap space would be consumed by httpd, negatively
impacting other processes, or causing a system crash. (CVE-2008-1678)

Note: The CVE-2008-1678 issue did not affect Red Hat Enterprise Linux 5
prior to 5.3. The problem was introduced via the RHBA-2009:0181 errata in
Red Hat Enterprise Linux 5.3, which upgraded OpenSSL to the newer 0.9.8e
version.

A flaw was found in the handling of the "Options" and "AllowOverride"
directives. In configurations using the "AllowOverride" directive with
certain "Options=" arguments, local users were not restricted from
executing commands from a Server-Side-Include script as intended.
(CVE-2009-1195)

All httpd users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Users must restart httpd for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-27" />
        <updated date="2009-05-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1678.html">CVE-2008-1678</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1195.html">CVE-2009-1195</cve>
                <bugzilla href="http://bugzilla.redhat.com/447268" id="447268">CVE-2008-1678 httpd: mod_ssl per-connection memory leak for connections with zlib compression</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489436" id="489436">CVE-2009-1195 AllowOverride Options=IncludesNoExec allows Options Includes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497077" id="497077">memory leak in httpd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075004" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075005" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075006" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075007" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075008" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075009" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075002" comment="httpd is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091082" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1082: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1082-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1082.html" />
          <reference source="CVE" ref_id="CVE-2009-0949" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0949.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. 

A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)

Red Hat would like to thank Anibal Sacco from Core Security Technologies
for reporting this issue.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-03" />
        <updated date="2009-06-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0949.html">CVE-2009-0949</cve>
                <bugzilla href="http://bugzilla.redhat.com/500972" id="500972">CVE-2009-0949 cups: IPP_TAG_UNSUPPORTED handling NULL pointer dereference DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082008" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082006" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082004" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082002" comment="cups is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091083" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1083: cups security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1083-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1083.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-0949" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0949.html" />
          <reference source="CVE" ref_id="CVE-2009-1196" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1196.html" />
    
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. The CUPS
"pdftops" filter converts Portable Document Format (PDF) files to
PostScript. "pdftops" is based on Xpdf and the CUPS imaging library.

A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)

A use-after-free flaw was found in the CUPS scheduler directory services
routine, used to process data about available printers and printer classes.
An attacker could use this flaw to cause a denial of service (cupsd daemon
stop or crash). (CVE-2009-1196)

Multiple integer overflows flaws, leading to heap-based buffer overflows,
were found in the CUPS "pdftops" filter. An attacker could create a
malicious PDF file that would cause "pdftops" to crash or, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0791)

Red Hat would like to thank Anibal Sacco from Core Security Technologies
for reporting the CVE-2009-0949 flaw, and Swen van Brussel for reporting
the CVE-2009-1196 flaw.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-03" />
        <updated date="2009-06-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0949.html">CVE-2009-0949</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1196.html">CVE-2009-1196</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 xpdf: multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497135" id="497135">CVE-2009-1196 cups: DoS (stop, crash) by  renewing CUPS browse packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500972" id="500972">CVE-2009-0949 cups: IPP_TAG_UNSUPPORTED handling NULL pointer dereference DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083006" comment="cups-devel is earlier than 1:1.1.17-13.3.62" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083004" comment="cups-libs is earlier than 1:1.1.17-13.3.62" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083002" comment="cups is earlier than 1:1.1.17-13.3.62" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083009" comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091095" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1095: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1095-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1095.html" />
          <reference source="CVE" ref_id="CVE-2009-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1392.html" />
          <reference source="CVE" ref_id="CVE-2009-1832" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1832.html" />
          <reference source="CVE" ref_id="CVE-2009-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1833.html" />
          <reference source="CVE" ref_id="CVE-2009-1834" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1834.html" />
          <reference source="CVE" ref_id="CVE-2009-1835" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1835.html" />
          <reference source="CVE" ref_id="CVE-2009-1836" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1836.html" />
          <reference source="CVE" ref_id="CVE-2009-1837" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1837.html" />
          <reference source="CVE" ref_id="CVE-2009-1838" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1838.html" />
          <reference source="CVE" ref_id="CVE-2009-1839" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1839.html" />
          <reference source="CVE" ref_id="CVE-2009-1840" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1840.html" />
          <reference source="CVE" ref_id="CVE-2009-1841" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1841.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1392, CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838,
CVE-2009-1841)

Multiple flaws were found in the processing of malformed, local file
content. If a user loaded malicious, local content via the file:// URL, it
was possible for that content to access other local data. (CVE-2009-1835,
CVE-2009-1839)

A script, privilege elevation flaw was found in the way Firefox loaded XML
User Interface Language (XUL) scripts. Firefox and certain add-ons could
load malicious content when certain policy checks did not happen.
(CVE-2009-1840)

A flaw was found in the way Firefox displayed certain Unicode characters in
International Domain Names (IDN). If an IDN contained invalid characters,
they may have been displayed as spaces, making it appear to the user that
they were visiting a trusted site. (CVE-2009-1834)

A flaw was found in the way Firefox handled error responses returned from
proxy servers. If an attacker is able to conduct a man-in-the-middle attack
against a Firefox instance that is using a proxy server, they may be able
to steal sensitive information from the site the user is visiting.
(CVE-2009-1836)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.11. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.11, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-11" />
        <updated date="2009-06-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1392.html">CVE-2009-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1832.html">CVE-2009-1832</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1833.html">CVE-2009-1833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1834.html">CVE-2009-1834</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1835.html">CVE-2009-1835</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1836.html">CVE-2009-1836</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1837.html">CVE-2009-1837</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1838.html">CVE-2009-1838</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1839.html">CVE-2009-1839</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1840.html">CVE-2009-1840</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1841.html">CVE-2009-1841</cve>
                <bugzilla href="http://bugzilla.redhat.com/488570" id="488570">frequent firefox crashes against clearspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503568" id="503568">CVE-2009-1392 Firefox browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503569" id="503569">CVE-2009-1832 Firefox double frame construction flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503570" id="503570">CVE-2009-1833 Firefox JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503573" id="503573">CVE-2009-1834 Firefox URL spoofing with invalid unicode characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503576" id="503576">CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503578" id="503578">CVE-2009-1836 Firefox SSL tampering via non-200 responses to proxy CONNECT requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503579" id="503579">CVE-2009-1837 Firefox Race condition while accessing the private data of a NPObject JS wrapper class object</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503580" id="503580">CVE-2009-1838 Firefox arbitrary code execution flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503581" id="503581">CVE-2009-1839 Firefox information disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503582" id="503582">CVE-2009-1840 Firefox XUL scripts skip some security checks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503583" id="503583">CVE-2009-1841 Firefox JavaScript arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095002" comment="firefox is earlier than 0:3.0.11-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095006" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095004" comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095008" comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091095011" comment="firefox is earlier than 0:3.0.11-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091096" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1096: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1096-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1096.html" />
          <reference source="CVE" ref_id="CVE-2009-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1392.html" />
          <reference source="CVE" ref_id="CVE-2009-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1833.html" />
          <reference source="CVE" ref_id="CVE-2009-1835" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1835.html" />
          <reference source="CVE" ref_id="CVE-2009-1838" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1838.html" />
          <reference source="CVE" ref_id="CVE-2009-1841" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1841.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1392, CVE-2009-1833, CVE-2009-1838, CVE-2009-1841)

A flaw was found in the processing of malformed, local file content. If a
user loaded malicious, local content via the file:// URL, it was possible
for that content to access other local data. (CVE-2009-1835)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-11" />
        <updated date="2009-06-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1392.html">CVE-2009-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1833.html">CVE-2009-1833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1835.html">CVE-2009-1835</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1838.html">CVE-2009-1838</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1841.html">CVE-2009-1841</cve>
                <bugzilla href="http://bugzilla.redhat.com/503568" id="503568">CVE-2009-1392 Firefox browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503570" id="503570">CVE-2009-1833 Firefox JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503576" id="503576">CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503580" id="503580">CVE-2009-1838 Firefox arbitrary code execution flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503583" id="503583">CVE-2009-1841 Firefox JavaScript arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096008" comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096020" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096014" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096004" comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096002" comment="seamonkey is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096010" comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096016" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096012" comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096006" comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096018" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096026" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096027" comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096023" comment="seamonkey is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096024" comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096028" comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096025" comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091100" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1100: wireshark security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1100.html" />
          <reference source="CVE" ref_id="CVE-2009-1210" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1210.html" />
          <reference source="CVE" ref_id="CVE-2009-1268" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1268.html" />
          <reference source="CVE" ref_id="CVE-2009-1269" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1269.html" />
          <reference source="CVE" ref_id="CVE-2009-1829" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1829.html" />
    
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A format string flaw was found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark. (CVE-2009-1210)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2009-1268, CVE-2009-1269, CVE-2009-1829)

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.8, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-15" />
        <updated date="2009-06-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1210.html">CVE-2009-1210</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1268.html">CVE-2009-1268</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1269.html">CVE-2009-1269</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1829.html">CVE-2009-1829</cve>
                <bugzilla href="http://bugzilla.redhat.com/493973" id="493973">CVE-2009-1210 wireshark: format string in PROFINET dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495119" id="495119">CVE-2009-1268 Wireshark CHAP dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495121" id="495121">CVE-2009-1269 Wireshark Tektronix .rf5 file crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501929" id="501929">CVE-2009-1829 wireshark: PCNFSD dissector crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100002" comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313003" comment="wireshark is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100004" comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313005" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100007" comment="wireshark is earlier than 0:1.0.8-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100009" comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100012" comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100013" comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091101" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1101: cscope security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1101-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1101.html" />
          <reference source="CVE" ref_id="CVE-2004-2541" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2541.html" />
          <reference source="CVE" ref_id="CVE-2006-4262" ref_url="https://www.redhat.com/security/data/cve/CVE-2006-4262.html" />
          <reference source="CVE" ref_id="CVE-2009-0148" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0148.html" />
          <reference source="CVE" ref_id="CVE-2009-1577" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1577.html" />
    
    <description>cscope is a mature, ncurses-based, C source-code tree browsing tool.

Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2006-4262, CVE-2009-0148, CVE-2009-1577)

All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-15" />
        <updated date="2009-06-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2541.html">CVE-2004-2541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2006-4262.html">CVE-2006-4262</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0148.html">CVE-2009-0148</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1577.html">CVE-2009-1577</cve>
                <bugzilla href="http://bugzilla.redhat.com/203645" id="203645">CVE-2006-4262 cscope: multiple buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490667" id="490667">CVE-2004-2541, CVE-2009-0148 cscope: multiple buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499174" id="499174">CVE-2009-1577 cscope: putstring buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101002" comment="cscope is earlier than 0:15.5-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101003" comment="cscope is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101005" comment="cscope is earlier than 0:15.5-10.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101003" comment="cscope is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091102" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1102: cscope security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1102.html" />
          <reference source="CVE" ref_id="CVE-2004-2541" ref_url="https://www.redhat.com/security/data/cve/CVE-2004-2541.html" />
          <reference source="CVE" ref_id="CVE-2009-0148" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0148.html" />
    
    <description>cscope is a mature, ncurses-based, C source-code tree browsing tool.

Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2009-0148)

All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-15" />
        <updated date="2009-06-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2004-2541.html">CVE-2004-2541</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0148.html">CVE-2009-0148</cve>
                <bugzilla href="http://bugzilla.redhat.com/490667" id="490667">CVE-2004-2541, CVE-2009-0148 cscope: multiple buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091102002" comment="cscope is earlier than 0:15.5-15.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091102003" comment="cscope is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091106" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1106: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1106-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1106.html" />
          <reference source="CVE" ref_id="CVE-2009-1072" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1072.html" />
          <reference source="CVE" ref_id="CVE-2009-1192" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1192.html" />
          <reference source="CVE" ref_id="CVE-2009-1439" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1439.html" />
          <reference source="CVE" ref_id="CVE-2009-1630" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1630.html" />
          <reference source="CVE" ref_id="CVE-2009-1633" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1633.html" />
          <reference source="CVE" ref_id="CVE-2009-1758" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1758.html" />
          <reference source="CVE" ref_id="CVE-2009-3238" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3238.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* several flaws were found in the way the Linux kernel CIFS implementation
handles Unicode strings. CIFS clients convert Unicode strings sent by a
server to their local character sets, and then write those strings into
memory. If a malicious server sent a long enough string, it could write
past the end of the target memory region and corrupt other memory areas,
possibly leading to a denial of service or privilege escalation on the
client mounting the CIFS share. (CVE-2009-1439, CVE-2009-1633, Important)

* the Linux kernel Network File System daemon (nfsd) implementation did not
drop the CAP_MKNOD capability when handling requests from local,
unprivileged users. This flaw could possibly lead to an information leak or
privilege escalation. (CVE-2009-1072, Moderate)

* Frank Filz reported the NFSv4 client was missing a file permission check
for the execute bit in some situations. This could allow local,
unprivileged users to run non-executable files on NFSv4 mounted file
systems. (CVE-2009-1630, Moderate)

* a missing check was found in the hypervisor_callback() function in the
Linux kernel provided by the kernel-xen package. This could cause a denial
of service of a 32-bit guest if an application running in that guest
accesses a certain memory location in the kernel. (CVE-2009-1758, Moderate)

* a flaw was found in the AGPGART driver. The agp_generic_alloc_page() and
agp_generic_alloc_pages() functions did not zero out the memory pages they
allocate, which may later be available to user-space processes. This flaw
could possibly lead to an information leak. (CVE-2009-1192, Low)

Bug fixes:

* a race in the NFS client between destroying cached access rights and
unmounting an NFS file system could have caused a system crash. "Busy
inodes" messages may have been logged. (BZ#498653)

* nanosleep() could sleep several milliseconds less than the specified time
on Intel Itanium®-based systems. (BZ#500349)

* LEDs for disk drives in AHCI mode may have displayed a fault state when
there were no faults. (BZ#500120)

* ptrace_do_wait() reported tasks were stopped each time the process doing
the trace called wait(), instead of reporting it once. (BZ#486945)

* epoll_wait() may have caused a system lockup and problems for
applications. (BZ#497322)

* missing capabilities could possibly allow users with an fsuid other than
0 to perform actions on some file system types that would otherwise be
prevented. (BZ#497271)

* on NFS mounted file systems, heavy write loads may have blocked
nfs_getattr() for long periods, causing commands that use stat(2), such as
ls, to hang. (BZ#486926)

* in rare circumstances, if an application performed multiple O_DIRECT
reads per virtual memory page and also performed fork(2), the buffer
storing the result of the I/O may have ended up with invalid data.
(BZ#486921)

* when using GFS2, gfs2_quotad may have entered an uninterpretable sleep
state. (BZ#501742)

* with this update, get_random_int() is more random and no longer uses a
common seed value, reducing the possibility of predicting the values
returned. (BZ#499783)

* the "-fwrapv" flag was added to the gcc build options to prevent gcc from
optimizing away wrapping. (BZ#501751)

* a kernel panic when enabling and disabling iSCSI paths. (BZ#502916)

* using the Broadcom NetXtreme BCM5704 network device with the tg3 driver
caused high system load and very bad performance. (BZ#502837)

* "/proc/[pid]/maps" and "/proc/[pid]/smaps" can only be read by processes
able to use the ptrace() call on a given process; however, certain
information from "/proc/[pid]/stat" and "/proc/[pid]/wchan" could be used
to reconstruct memory maps. (BZ#499546)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-16" />
        <updated date="2009-06-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1072.html">CVE-2009-1072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1192.html">CVE-2009-1192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1439.html">CVE-2009-1439</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1630.html">CVE-2009-1630</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1633.html">CVE-2009-1633</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1758.html">CVE-2009-1758</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3238.html">CVE-2009-3238</cve>
                <bugzilla href="http://bugzilla.redhat.com/486921" id="486921">Corruption on ext3/xfs with O_DIRECT and unaligned user buffers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486926" id="486926">[RHEL5.2] nfs_getattr() hangs during heavy write workloads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486945" id="486945">waitpid() reports stopped process more than once</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491572" id="491572">CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494275" id="494275">CVE-2009-1439 kernel: cifs: memory overwrite when saving nativeFileSystem field during mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496572" id="496572">CVE-2009-1633 kernel: cifs: fix potential buffer overruns when converting unicode strings sent by server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497020" id="497020">CVE-2009-1192 kernel: agp: zero pages before sending to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497322" id="497322">crm #1896100 port epoll_wait fix from RHSA-2008-0665 to RHEL 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498653" id="498653">fault in iget() - suspected race between nfs_access_cache_shrinker() and umount - Ref.: Bug #433249</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499546" id="499546">kernel: proc: avoid information leaks to non-privileged processes [rhel-5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500120" id="500120">Problem with drive status leds after update to 2.6.18-128.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500297" id="500297">CVE-2009-1630 kernel: nfs: fix NFS v4 client handling of MAY_EXEC in nfs_permission</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500349" id="500349">RHEL5.3.z LTP nanosleep02 Test Case Failure on Fujitsu Machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500945" id="500945">CVE-2009-1758 kernel: xen: local denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501742" id="501742">GFS2: gfs2_quotad in uninterruptible sleep while idle</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501751" id="501751">kernel should be built with -fwrapv [rhel-5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502837" id="502837">BCM5704 NIC results in CPU 100%SI , sluggish system performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502916" id="502916">kernel BUG at drivers/scsi/libiscsi.c:301!</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106004" comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106002" comment="kernel is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106024" comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106020" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106006" comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106010" comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106016" comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106014" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106012" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106022" comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106018" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091106008" comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091107" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1107: apr-util security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1107-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1107.html" />
          <reference source="CVE" ref_id="CVE-2009-0023" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0023.html" />
          <reference source="CVE" ref_id="CVE-2009-1955" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1955.html" />
          <reference source="CVE" ref_id="CVE-2009-1956" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1956.html" />
    
    <description>apr-util is a utility library used with the Apache Portable Runtime (APR).
It aims to provide a free library of C data structures and routines. This
library contains additional utility interfaces for APR; including support
for XML, LDAP, database interfaces, URI parsing, and more.

An off-by-one overflow flaw was found in the way apr-util processed a
variable list of arguments. An attacker could provide a specially-crafted
string as input for the formatted output conversion routine, which could,
on big-endian platforms, potentially lead to the disclosure of sensitive
information or a denial of service (application crash). (CVE-2009-1956)

Note: The CVE-2009-1956 flaw only affects big-endian platforms, such as the
IBM S/390 and PowerPC. It does not affect users using the apr-util package
on little-endian platforms, due to their different organization of byte
ordering used to represent particular data.

A denial of service flaw was found in the apr-util Extensible Markup
Language (XML) parser. A remote attacker could create a specially-crafted
XML document that would cause excessive memory consumption when processed
by the XML decoding engine. (CVE-2009-1955)

A heap-based underwrite flaw was found in the way apr-util created compiled
forms of particular search patterns. An attacker could formulate a
specially-crafted search keyword, that would overwrite arbitrary heap
memory locations when processed by the pattern preparation engine.
(CVE-2009-0023)

All apr-util users should upgrade to these updated packages, which contain
backported patches to correct these issues. Applications using the Apache
Portable Runtime library, such as httpd, must be restarted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-16" />
        <updated date="2009-06-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0023.html">CVE-2009-0023</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1955.html">CVE-2009-1955</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1956.html">CVE-2009-1956</cve>
                <bugzilla href="http://bugzilla.redhat.com/503928" id="503928">CVE-2009-0023 apr-util heap buffer underwrite</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504390" id="504390">CVE-2009-1956 apr-util single NULL byte buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504555" id="504555">CVE-2009-1955 apr-util billion laughs attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091107002" comment="apr-util is earlier than 0:1.2.7-7.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107003" comment="apr-util is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091107004" comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107005" comment="apr-util-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091107006" comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107007" comment="apr-util-docs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091107009" comment="apr-util is earlier than 0:0.9.4-22.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107010" comment="apr-util is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091107011" comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107012" comment="apr-util-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091108" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1108: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1108-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1108.html" />
          <reference source="CVE" ref_id="CVE-2009-0023" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0023.html" />
          <reference source="CVE" ref_id="CVE-2009-1955" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1955.html" />
          <reference source="CVE" ref_id="CVE-2009-1956" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1956.html" />
    
    <description>The Apache HTTP Server is a popular Web server. The httpd package shipped
with Red Hat Enterprise Linux 3 contains an embedded copy of the Apache
Portable Runtime (APR) utility library, a free library of C data structures
and routines, which includes interfaces to support XML parsing, LDAP
connections, database interfaces, URI parsing, and more.

An off-by-one overflow flaw was found in the way apr-util processed a
variable list of arguments. An attacker could provide a specially-crafted
string as input for the formatted output conversion routine, which could,
on big-endian platforms, potentially lead to the disclosure of sensitive
information or a denial of service (application crash). (CVE-2009-1956)

Note: The CVE-2009-1956 flaw only affects big-endian platforms, such as the
IBM S/390 and PowerPC. It does not affect users using the httpd package on
little-endian platforms, due to their different organization of byte
ordering used to represent particular data.

A denial of service flaw was found in the apr-util Extensible Markup
Language (XML) parser. A remote attacker could create a specially-crafted
XML document that would cause excessive memory consumption when processed
by the XML decoding engine. (CVE-2009-1955)

A heap-based underwrite flaw was found in the way apr-util created compiled
forms of particular search patterns. An attacker could formulate a
specially-crafted search keyword, that would overwrite arbitrary heap
memory locations when processed by the pattern preparation engine.
(CVE-2009-0023)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-16" />
        <updated date="2009-06-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0023.html">CVE-2009-0023</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1955.html">CVE-2009-1955</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1956.html">CVE-2009-1956</cve>
                <bugzilla href="http://bugzilla.redhat.com/503928" id="503928">CVE-2009-0023 apr-util heap buffer underwrite</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504390" id="504390">CVE-2009-1956 apr-util single NULL byte buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504555" id="504555">CVE-2009-1955 apr-util billion laughs attack</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091108004" comment="httpd-devel is earlier than 0:2.0.46-73.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091108006" comment="mod_ssl is earlier than 0:2.0.46-73.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091108002" comment="httpd is earlier than 0:2.0.46-73.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091109" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1109: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1109-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1109.html" />
          <reference source="CVE" ref_id="CVE-2009-0198" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0198.html" />
          <reference source="CVE" ref_id="CVE-2009-0509" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0509.html" />
          <reference source="CVE" ref_id="CVE-2009-0510" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0510.html" />
          <reference source="CVE" ref_id="CVE-2009-0511" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0511.html" />
          <reference source="CVE" ref_id="CVE-2009-0512" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0512.html" />
          <reference source="CVE" ref_id="CVE-2009-0888" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0888.html" />
          <reference source="CVE" ref_id="CVE-2009-0889" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0889.html" />
          <reference source="CVE" ref_id="CVE-2009-1855" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1855.html" />
          <reference source="CVE" ref_id="CVE-2009-1856" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1856.html" />
          <reference source="CVE" ref_id="CVE-2009-1857" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1857.html" />
          <reference source="CVE" ref_id="CVE-2009-1858" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1858.html" />
          <reference source="CVE" ref_id="CVE-2009-1859" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1859.html" />
          <reference source="CVE" ref_id="CVE-2009-1861" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1861.html" />
          <reference source="CVE" ref_id="CVE-2009-2028" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2028.html" />
    
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

Multiple security flaws were discovered in Adobe Reader. A specially
crafted PDF file could cause Adobe Reader to crash or, potentially, execute
arbitrary code as the user running Adobe Reader when opened.
(CVE-2009-0198, CVE-2009-0509, CVE-2009-0510, CVE-2009-0511, CVE-2009-0512,
CVE-2009-0888, CVE-2009-0889, CVE-2009-1855, CVE-2009-1856, CVE-2009-1857,
CVE-2009-1858, CVE-2009-1859, CVE-2009-1861, CVE-2009-2028)

All Adobe Reader users should install these updated packages. They contain
Adobe Reader version 8.1.6, which is not vulnerable to these issues. All
running instances of Adobe Reader must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-17" />
        <updated date="2009-06-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0198.html">CVE-2009-0198</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0509.html">CVE-2009-0509</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0510.html">CVE-2009-0510</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0511.html">CVE-2009-0511</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0512.html">CVE-2009-0512</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0888.html">CVE-2009-0888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0889.html">CVE-2009-0889</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1855.html">CVE-2009-1855</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1856.html">CVE-2009-1856</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1857.html">CVE-2009-1857</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1858.html">CVE-2009-1858</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1859.html">CVE-2009-1859</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1861.html">CVE-2009-1861</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2028.html">CVE-2009-2028</cve>
                <bugzilla href="http://bugzilla.redhat.com/505049" id="505049">acroread: multiple security fixes in version 8.1.6 (APSB09-07)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091109004" comment="acroread-plugin is earlier than 0:8.1.6-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091109002" comment="acroread is earlier than 0:8.1.6-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091116" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1116: cyrus-imapd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1116-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1116.html" />
          <reference source="CVE" ref_id="CVE-2009-0688" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0688.html" />
    
    <description>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and SIEVE support.

It was discovered that the Cyrus SASL library (cyrus-sasl) does not always
reliably terminate output from the sasl_encode64() function used by
programs using this library. The Cyrus IMAP server (cyrus-imapd) relied on
this function's output being properly terminated. Under certain conditions,
improperly terminated output from sasl_encode64() could, potentially, cause
cyrus-imapd to crash, disclose portions of its memory, or lead to SASL
authentication failures. (CVE-2009-0688)

Users of cyrus-imapd are advised to upgrade to these updated packages,
which resolve this issue. After installing the update, cyrus-imapd will be
restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-18" />
        <updated date="2009-06-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0688.html">CVE-2009-0688</cve>
                <bugzilla href="http://bugzilla.redhat.com/504207" id="504207">CVE-2009-0688 cyrus-imapd uses sasl_encode64() improperly</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116008" comment="cyrus-imapd-perl is earlier than 0:2.3.7-2.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116009" comment="cyrus-imapd-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116002" comment="cyrus-imapd is earlier than 0:2.3.7-2.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116003" comment="cyrus-imapd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116006" comment="cyrus-imapd-devel is earlier than 0:2.3.7-2.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116007" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116004" comment="cyrus-imapd-utils is earlier than 0:2.3.7-2.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116005" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116021" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116022" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116015" comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116016" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116011" comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116012" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116019" comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116020" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116013" comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116014" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091116017" comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116018" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091122" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1122: icu security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1122-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1122.html" />
          <reference source="CVE" ref_id="CVE-2009-0153" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0153.html" />
    
    <description>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

A flaw was found in the way ICU processed certain, invalid byte sequences
during Unicode conversion. If an application used ICU to decode malformed,
multibyte character data, it may have been possible to bypass certain
content protection mechanisms, or display information in a manner
misleading to the user. (CVE-2009-0153)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0153.html">CVE-2009-0153</cve>
                <bugzilla href="http://bugzilla.redhat.com/503071" id="503071">CVE-2009-0153 icu: XSS vulnerability due to improper invalid byte sequence handling</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091122008" comment="libicu is earlier than 0:3.6-5.11.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296007" comment="libicu is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091122006" comment="libicu-doc is earlier than 0:3.6-5.11.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296005" comment="libicu-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091122004" comment="libicu-devel is earlier than 0:3.6-5.11.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296009" comment="libicu-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091122002" comment="icu is earlier than 0:3.6-5.11.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296003" comment="icu is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091123" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1123: gstreamer-plugins-good security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1123-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1123.html" />
          <reference source="CVE" ref_id="CVE-2009-1932" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1932.html" />
    
    <description>GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, good quality GStreamer plug-ins.

Multiple integer overflow flaws, that could lead to a buffer overflow, were
found in the GStreamer Good Plug-ins PNG decoding handler. An attacker
could create a specially-crafted PNG file that would cause an application
using the GStreamer Good Plug-ins library to crash or, potentially, execute
arbitrary code as the user running the application when parsed.
(CVE-2009-1932)

All users of gstreamer-plugins-good are advised to upgrade to these updated
packages, which contain a backported patch to correct these issues. After
installing the update, all applications using GStreamer Good Plug-ins (such
as some media playing applications) must be restarted for the changes to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1932.html">CVE-2009-1932</cve>
                <bugzilla href="http://bugzilla.redhat.com/504199" id="504199">CVE-2009-1932 gstreamer-plugins-good: PNG decoder integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091123004" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090271005" comment="gstreamer-plugins-good-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091123002" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090271003" comment="gstreamer-plugins-good is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091124" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1124: net-snmp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1124-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1124.html" />
          <reference source="CVE" ref_id="CVE-2009-1887" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1887.html" />
    
    <description>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

A divide-by-zero flaw was discovered in the snmpd daemon. A remote attacker
could issue a specially-crafted GETBULK request that could crash the snmpd
daemon. (CVE-2009-1887)

Note: An attacker must have read access to the SNMP server in order to
exploit this flaw. In the default configuration, the community name
"public" grants read-only access. In production deployments, it is
recommended to change this default community name.

All net-snmp users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the update, the
snmpd and snmptrapd daemons will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1887.html">CVE-2009-1887</cve>
                <bugzilla href="http://bugzilla.redhat.com/506903" id="506903">CVE-2009-1887 net-snmp: DoS (division by zero) via SNMP GetBulk requests</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091124010" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295007" comment="net-snmp-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091124008" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295009" comment="net-snmp-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091124006" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295005" comment="net-snmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091124004" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295011" comment="net-snmp-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091124002" comment="net-snmp is earlier than 0:5.0.9-2.30E.28" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295003" comment="net-snmp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091125" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1125: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1125-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1125.html" />
          <reference source="CVE" ref_id="CVE-2009-1303" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1303.html" />
          <reference source="CVE" ref_id="CVE-2009-1305" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1305.html" />
          <reference source="CVE" ref_id="CVE-2009-1306" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1306.html" />
          <reference source="CVE" ref_id="CVE-2009-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1307.html" />
          <reference source="CVE" ref_id="CVE-2009-1309" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1309.html" />
          <reference source="CVE" ref_id="CVE-2009-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1392.html" />
          <reference source="CVE" ref_id="CVE-2009-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1833.html" />
          <reference source="CVE" ref_id="CVE-2009-1838" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1838.html" />
          <reference source="CVE" ref_id="CVE-2009-2210" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2210.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-1392, CVE-2009-1303, CVE-2009-1305, CVE-2009-1833,
CVE-2009-1838)

Several flaws were found in the way malformed HTML mail content was
processed. An HTML mail message containing malicious content could execute
arbitrary JavaScript in the context of the mail message, possibly
presenting misleading data to the user, or stealing sensitive information
such as login credentials. (CVE-2009-1306, CVE-2009-1307, CVE-2009-1309)

Note: JavaScript support is disabled by default in Thunderbird. None of the
above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1303.html">CVE-2009-1303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1305.html">CVE-2009-1305</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1306.html">CVE-2009-1306</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1307.html">CVE-2009-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1309.html">CVE-2009-1309</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1392.html">CVE-2009-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1833.html">CVE-2009-1833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1838.html">CVE-2009-1838</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2210.html">CVE-2009-2210</cve>
                <bugzilla href="http://bugzilla.redhat.com/496253" id="496253">CVE-2009-1303 Firefox 2 and 3 Layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496256" id="496256">CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496262" id="496262">CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496263" id="496263">CVE-2009-1307 Firefox Same-origin violations when Adobe Flash loaded via view-source: protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496267" id="496267">CVE-2009-1309 Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503568" id="503568">CVE-2009-1392 Firefox browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503570" id="503570">CVE-2009-1833 Firefox JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503580" id="503580">CVE-2009-1838 Firefox arbitrary code execution flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091125002" comment="thunderbird is earlier than 0:1.5.0.12-23.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002006" comment="thunderbird is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091126" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1126: thunderbird security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1126-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1126.html" />
          <reference source="CVE" ref_id="CVE-2009-1303" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1303.html" />
          <reference source="CVE" ref_id="CVE-2009-1305" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1305.html" />
          <reference source="CVE" ref_id="CVE-2009-1306" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1306.html" />
          <reference source="CVE" ref_id="CVE-2009-1307" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1307.html" />
          <reference source="CVE" ref_id="CVE-2009-1308" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1308.html" />
          <reference source="CVE" ref_id="CVE-2009-1309" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1309.html" />
          <reference source="CVE" ref_id="CVE-2009-1392" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1392.html" />
          <reference source="CVE" ref_id="CVE-2009-1833" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1833.html" />
          <reference source="CVE" ref_id="CVE-2009-1836" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1836.html" />
          <reference source="CVE" ref_id="CVE-2009-1838" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1838.html" />
          <reference source="CVE" ref_id="CVE-2009-2210" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2210.html" />
    
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-1392, CVE-2009-1303, CVE-2009-1305, CVE-2009-1833,
CVE-2009-1838)

Several flaws were found in the way malformed HTML mail content was
processed. An HTML mail message containing malicious content could execute
arbitrary JavaScript in the context of the mail message, possibly
presenting misleading data to the user, or stealing sensitive information
such as login credentials. (CVE-2009-1306, CVE-2009-1307, CVE-2009-1308,
CVE-2009-1309)

A flaw was found in the way Thunderbird handled error responses returned
from proxy servers. If an attacker is able to conduct a man-in-the-middle
attack against a Thunderbird instance that is using a proxy server, they
may be able to steal sensitive information from the site Thunderbird is
displaying. (CVE-2009-1836)

Note: JavaScript support is disabled by default in Thunderbird. None of the
above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1303.html">CVE-2009-1303</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1305.html">CVE-2009-1305</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1306.html">CVE-2009-1306</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1307.html">CVE-2009-1307</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1308.html">CVE-2009-1308</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1309.html">CVE-2009-1309</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1392.html">CVE-2009-1392</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1833.html">CVE-2009-1833</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1836.html">CVE-2009-1836</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1838.html">CVE-2009-1838</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2210.html">CVE-2009-2210</cve>
                <bugzilla href="http://bugzilla.redhat.com/456202" id="456202">Launch thunderbird with option "-contentLocale" &lt;locale> will get warning message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496253" id="496253">CVE-2009-1303 Firefox 2 and 3 Layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496256" id="496256">CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496262" id="496262">CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496263" id="496263">CVE-2009-1307 Firefox Same-origin violations when Adobe Flash loaded via view-source: protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496266" id="496266">CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496267" id="496267">CVE-2009-1309 Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503568" id="503568">CVE-2009-1392 Firefox browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503570" id="503570">CVE-2009-1833 Firefox JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503578" id="503578">CVE-2009-1836 Firefox SSL tampering via non-200 responses to proxy CONNECT requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503580" id="503580">CVE-2009-1838 Firefox arbitrary code execution flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091126002" comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090002003" comment="thunderbird is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091127" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1127: kdelibs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1127-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1127.html" />
          <reference source="CVE" ref_id="CVE-2009-1687" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1687.html" />
          <reference source="CVE" ref_id="CVE-2009-1690" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1690.html" />
          <reference source="CVE" ref_id="CVE-2009-1698" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1698.html" />
    
    <description>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A flaw was found in the way the KDE CSS parser handled content for the
CSS "style" attribute. A remote attacker could create a specially-crafted
CSS equipped HTML page, which once visited by an unsuspecting user, could
cause a denial of service (Konqueror crash) or, potentially, execute
arbitrary code with the privileges of the user running Konqueror.
(CVE-2009-1698)

A flaw was found in the way the KDE HTML parser handled content for the
HTML "head" element. A remote attacker could create a specially-crafted
HTML page, which once visited by an unsuspecting user, could cause a denial
of service (Konqueror crash) or, potentially, execute arbitrary code with
the privileges of the user running Konqueror. (CVE-2009-1690)

An integer overflow flaw, leading to a heap-based buffer overflow, was
found in the way the KDE JavaScript garbage collector handled memory
allocation requests. A remote attacker could create a specially-crafted
HTML page, which once visited by an unsuspecting user, could cause a denial
of service (Konqueror crash) or, potentially, execute arbitrary code with
the privileges of the user running Konqueror. (CVE-2009-1687)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The desktop must be restarted (log out,
then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1687.html">CVE-2009-1687</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1690.html">CVE-2009-1690</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1698.html">CVE-2009-1698</cve>
                <bugzilla href="http://bugzilla.redhat.com/505571" id="505571">CVE-2009-1690 kdelibs: KHTML Incorrect handling &lt;head> element content once the &lt;head> element was removed (DoS, ACE)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506453" id="506453">CVE-2009-1687 kdelibs: Integer overflow in KJS JavaScript garbage collector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506469" id="506469">CVE-2009-1698 kdelibs: KHTML CSS parser - incorrect handling CSS "style" attribute content (DoS, ACE)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091127004" comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127005" comment="kdelibs-apidocs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091127002" comment="kdelibs is earlier than 6:3.5.4-22.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127003" comment="kdelibs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091127006" comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127007" comment="kdelibs-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091127009" comment="kdelibs is earlier than 6:3.3.1-14.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127010" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091127011" comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127012" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091128" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1128: kdelibs security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1128-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1128.html" />
          <reference source="CVE" ref_id="CVE-2009-1698" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1698.html" />
    
    <description>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A flaw was found in the way the KDE CSS parser handled content for the
CSS "style" attribute. A remote attacker could create a specially-crafted
CSS equipped HTML page, which once visited by an unsuspecting user, could
cause a denial of service (Konqueror crash) or, potentially, execute
arbitrary code with the privileges of the user running Konqueror.
(CVE-2009-1698)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The desktop must be restarted (log out, then
log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1698.html">CVE-2009-1698</cve>
                <bugzilla href="http://bugzilla.redhat.com/506469" id="506469">CVE-2009-1698 kdelibs: KHTML CSS parser - incorrect handling CSS "style" attribute content (DoS, ACE)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091128002" comment="kdelibs is earlier than 6:3.1.3-6.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127010" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091128004" comment="kdelibs-devel is earlier than 6:3.1.3-6.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127012" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091130" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1130: kdegraphics security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1130-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1130.html" />
          <reference source="CVE" ref_id="CVE-2009-0945" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0945.html" />
          <reference source="CVE" ref_id="CVE-2009-1709" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1709.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop Environment
(KDE). Scalable Vector Graphics (SVG) is an XML-based language to describe
vector images. KSVG is a framework aimed at implementing the latest W3C SVG
specifications.

A use-after-free flaw was found in the KDE KSVG animation element
implementation. A remote attacker could create a specially-crafted SVG
image, which once opened by an unsuspecting user, could cause a denial of
service (Konqueror crash) or, potentially, execute arbitrary code with the
privileges of the user running Konqueror. (CVE-2009-1709)

A NULL pointer dereference flaw was found in the KDE, KSVG SVGList
interface implementation. A remote attacker could create a
specially-crafted SVG image, which once opened by an unsuspecting user,
would cause memory corruption, leading to a denial of service (Konqueror
crash). (CVE-2009-0945)

All users of kdegraphics should upgrade to these updated packages, which
contain backported patches to correct these issues. The desktop must be
restarted (log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-25" />
        <updated date="2009-06-25" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0945.html">CVE-2009-0945</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1709.html">CVE-2009-1709</cve>
                <bugzilla href="http://bugzilla.redhat.com/506246" id="506246">CVE-2009-1709 kdegraphics: KSVG Pointer use-after-free error in the SVG animation element (DoS, ACE)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506703" id="506703">CVE-2009-0945 kdegraphics: KSVG NULL-pointer dereference in the SVGList interface implementation (ACE)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091130002" comment="kdegraphics is earlier than 7:3.5.4-13.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431003" comment="kdegraphics is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091130004" comment="kdegraphics-devel is earlier than 7:3.5.4-13.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431005" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091132" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1132: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1132-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1132.html" />
          <reference source="CVE" ref_id="CVE-2009-1072" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1072.html" />
          <reference source="CVE" ref_id="CVE-2009-1192" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1192.html" />
          <reference source="CVE" ref_id="CVE-2009-1385" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1385.html" />
          <reference source="CVE" ref_id="CVE-2009-1630" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1630.html" />
          <reference source="CVE" ref_id="CVE-2009-1758" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1758.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the Intel PRO/1000 network driver in the Linux
kernel. Frames with sizes near the MTU of an interface may be split across
multiple hardware receive descriptors. Receipt of such a frame could leak
through a validation check, leading to a corruption of the length check. A
remote attacker could use this flaw to send a specially-crafted packet that
would cause a denial of service. (CVE-2009-1385, Important)

* the Linux kernel Network File System daemon (nfsd) implementation did not
drop the CAP_MKNOD capability when handling requests from local,
unprivileged users. This flaw could possibly lead to an information leak or
privilege escalation. (CVE-2009-1072, Moderate)

* Frank Filz reported the NFSv4 client was missing a file permission check
for the execute bit in some situations. This could allow local,
unprivileged users to run non-executable files on NFSv4 mounted file
systems. (CVE-2009-1630, Moderate)

* a missing check was found in the hypervisor_callback() function in the
Linux kernel provided by the kernel-xen package. This could cause a denial
of service of a 32-bit guest if an application running in that guest
accesses a certain memory location in the kernel. (CVE-2009-1758, Moderate)

* a flaw was found in the AGPGART driver. The agp_generic_alloc_page() and
agp_generic_alloc_pages() functions did not zero out the memory pages they
allocate, which may later be available to user-space processes. This flaw
could possibly lead to an information leak. (CVE-2009-1192, Low)

These updated packages also fix the following bugs:

* "/proc/[pid]/maps" and "/proc/[pid]/smaps" can only be read by processes
able to use the ptrace() call on a given process; however, certain
information from "/proc/[pid]/stat" and "/proc/[pid]/wchan" could be used
to reconstruct memory maps, making it possible to bypass the Address Space
Layout Randomization (ASLR) security feature. This update addresses this
issue. (BZ#499549)

* in some situations, the link count was not decreased when renaming unused
files on NFS mounted file systems. This may have resulted in poor
performance. With this update, the link count is decreased in these
situations, the same as is done for other file operations, such as unlink
and rmdir. (BZ#501802)

* tcp_ack() cleared the probes_out variable even if there were outstanding
packets. When low TCP keepalive intervals were used, this bug may have
caused problems, such as connections terminating, when using remote tools
such as rsh and rlogin. (BZ#501754)

* off-by-one errors in the time normalization code could have caused
clock_gettime() to return one billion nanoseconds, rather than adding an
extra second. This bug could have caused the name service cache daemon
(nscd) to consume excessive CPU resources. (BZ#501800)

* a system panic could occur when one thread read "/proc/bus/input/devices"
while another was removing a device. With this update, a mutex has been
added to protect the input_dev_list and input_handler_list variables, which
resolves this issue. (BZ#501804)

* using netdump may have caused a kernel deadlock on some systems.
(BZ#504565)

* the file system mask, which lists capabilities for users with a file
system user ID (fsuid) of 0, was missing the CAP_MKNOD and
CAP_LINUX_IMMUTABLE capabilities. This could, potentially, allow users with
an fsuid other than 0 to perform actions on some file system types that
would otherwise be prevented. This update adds these capabilities. (BZ#497269)

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues. Note:
The system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-30" />
        <updated date="2009-06-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1072.html">CVE-2009-1072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1192.html">CVE-2009-1192</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1385.html">CVE-2009-1385</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1630.html">CVE-2009-1630</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1758.html">CVE-2009-1758</cve>
                <bugzilla href="http://bugzilla.redhat.com/491572" id="491572">CVE-2009-1072 kernel: nfsd should drop CAP_MKNOD for non-root</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497020" id="497020">CVE-2009-1192 kernel: agp: zero pages before sending to userspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499549" id="499549">kernel: proc: avoid information leaks to non-privileged processes [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500297" id="500297">CVE-2009-1630 kernel: nfs: fix NFS v4 client handling of MAY_EXEC in nfs_permission</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500945" id="500945">CVE-2009-1758 kernel: xen: local denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501754" id="501754">Bug with TCP tcp_ack() [RHEL 4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501800" id="501800">[RHEL4] Nscd consumes many cpu resources ( nearly 100% ) continuously.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501802" id="501802">[RHEL 4] inode of the overwritten file will remain in the icache causing performance issues.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501804" id="501804">[Stratus 4.9 bug] panic reading /proc/bus/input/devices during input device removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502981" id="502981">CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504565" id="504565">e1000e: sporadic hang in netdump</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132002" comment="kernel is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132022" comment="kernel-doc is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132004" comment="kernel-devel is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132008" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132020" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132006" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132012" comment="kernel-xenU is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132010" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091132014" comment="kernel-smp is earlier than 0:2.6.9-89.0.3.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091134" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1134: seamonkey security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1134-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1134.html" />
          <reference source="CVE" ref_id="CVE-2009-2210" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2210.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way that SeaMonkey parsed malformed HTML mail
messages. If a user opened a specially-crafted HTML mail message, it could
cause SeaMonkey to crash or, possibly, to execute arbitrary code as the
user running SeaMonkey. (CVE-2009-2210)

All SeaMonkey users should upgrade to these updated packages, which correct
this issue. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-30" />
        <updated date="2009-06-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2210.html">CVE-2009-2210</cve>
                <bugzilla href="http://bugzilla.redhat.com/507812" id="507812">CVE-2009-2210 Thunderbird mail crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134020" comment="seamonkey-nspr is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134014" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134012" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134008" comment="seamonkey-mail is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134002" comment="seamonkey is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134004" comment="seamonkey-devel is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134018" comment="seamonkey-chat is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134016" comment="seamonkey-nss is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134006" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.39.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134026" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-44.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134025" comment="seamonkey-mail is earlier than 0:1.0.9-44.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134023" comment="seamonkey is earlier than 0:1.0.9-44.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134027" comment="seamonkey-devel is earlier than 0:1.0.9-44.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134024" comment="seamonkey-chat is earlier than 0:1.0.9-44.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091134028" comment="seamonkey-js-debugger is earlier than 0:1.0.9-44.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091136" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1136: dhcp security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1136-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1136.html" />
          <reference source="CVE" ref_id="CVE-2009-0692" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0692.html" />
    
    <description>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

The Mandriva Linux Engineering Team discovered a stack-based buffer
overflow flaw in the ISC DHCP client. If the DHCP client were to receive a
malicious DHCP response, it could crash or execute arbitrary code with the
permissions of the client (root). (CVE-2009-0692)

Users of DHCP should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-14" />
        <updated date="2009-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0692.html">CVE-2009-0692</cve>
                <bugzilla href="http://bugzilla.redhat.com/507717" id="507717">CVE-2009-0692 dhclient: stack overflow leads to arbitrary code execution as root</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091136006" comment="dhclient is earlier than 7:3.0.1-65.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091136007" comment="dhclient is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091136004" comment="dhcp-devel is earlier than 7:3.0.1-65.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091136005" comment="dhcp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091136002" comment="dhcp is earlier than 7:3.0.1-65.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091136003" comment="dhcp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091138" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1138: openswan security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1138-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1138.html" />
          <reference source="CVE" ref_id="CVE-2009-2185" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2185.html" />
    
    <description>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).

Multiple insufficient input validation flaws were found in the way
Openswan's pluto IKE daemon processed some fields of X.509 certificates. A
remote attacker could provide a specially-crafted X.509 certificate that
would crash the pluto daemon. (CVE-2009-2185)

All users of openswan are advised to upgrade to these updated packages,
which contain a backported patch to correct these issues. After installing
this update, the ipsec service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-02" />
        <updated date="2009-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2185.html">CVE-2009-2185</cve>
                <bugzilla href="http://bugzilla.redhat.com/507362" id="507362">CVE-2009-2185 Openswan ASN.1 parser vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091138002" comment="openswan is earlier than 0:2.6.14-1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090402003" comment="openswan is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091138004" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090402005" comment="openswan-doc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091139" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1139: pidgin security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1139-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1139.html" />
          <reference source="CVE" ref_id="CVE-2009-1889" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1889.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for CommunicAtion in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

A denial of service flaw was found in the Pidgin OSCAR protocol
implementation. If a remote ICQ user sent a web message to a local Pidgin
user using this protocol, it would cause excessive memory usage, leading to
a denial of service (Pidgin crash). (CVE-2009-1889)

These updated packages also fix the following bug:

* the Yahoo! Messenger Protocol changed, making it incompatible (and
unusable) with Pidgin versions prior to 2.5.7. This update provides Pidgin
2.5.8, which implements version 16 of the Yahoo! Messenger Protocol, which
resolves this issue.

Note: These packages upgrade Pidgin to version 2.5.8. Refer to the Pidgin
release notes for a full list of changes:
http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
these issues. Pidgin must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-02" />
        <updated date="2009-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1889.html">CVE-2009-1889</cve>
                <bugzilla href="http://bugzilla.redhat.com/508271" id="508271">pidgin Yahoo protocol 16 [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508272" id="508272">pidgin Yahoo protocol 16 [rhel-5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508738" id="508738">CVE-2009-1889 pidgin: DoS via specially-crafted ICQWebMessage</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139018" comment="libpurple-perl is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060011" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139014" comment="finch is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060017" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139012" comment="libpurple is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060009" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139002" comment="pidgin is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139016" comment="pidgin-devel is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139010" comment="pidgin-perl is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060013" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139008" comment="finch-devel is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060007" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139006" comment="libpurple-devel is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060005" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139004" comment="libpurple-tcl is earlier than 0:2.5.8-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060015" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139035" comment="finch is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060032" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139031" comment="libpurple-perl is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060038" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139023" comment="libpurple is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060030" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139021" comment="pidgin is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139037" comment="pidgin-devel is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060036" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139033" comment="pidgin-perl is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060028" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139027" comment="libpurple-devel is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060026" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139025" comment="finch-devel is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060034" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091139029" comment="libpurple-tcl is earlier than 0:2.5.8-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060024" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091140" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1140: ruby security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1140-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1140.html" />
          <reference source="CVE" ref_id="CVE-2007-1558" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-1558.html" />
          <reference source="CVE" ref_id="CVE-2009-0642" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0642.html" />
          <reference source="CVE" ref_id="CVE-2009-1904" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1904.html" />
    
    <description>Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.

A flaw was found in the way the Ruby POP module processed certain APOP
authentication requests. By sending certain responses when the Ruby APOP
module attempted to authenticate using APOP against a POP server, a remote
attacker could, potentially, acquire certain portions of a user's
authentication credentials. (CVE-2007-1558)

It was discovered that Ruby did not properly check the return value when
verifying X.509 certificates. This could, potentially, allow a remote
attacker to present an invalid X.509 certificate, and have Ruby treat it as
valid. (CVE-2009-0642)

A flaw was found in the way Ruby converted BigDecimal objects to Float
numbers. If an attacker were able to provide certain input for the
BigDecimal object converter, they could crash an application using this
class. (CVE-2009-1904)

All Ruby users should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-02" />
        <updated date="2009-07-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-1558.html">CVE-2007-1558</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0642.html">CVE-2009-0642</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1904.html">CVE-2009-1904</cve>
                <bugzilla href="http://bugzilla.redhat.com/241191" id="241191">CVE-2007-1558 fetchmail/mutt/evolution/...: APOP password disclosure vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486183" id="486183">CVE-2009-0642 ruby: Incorrect checks for validity of X.509 certificates</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504958" id="504958">CVE-2009-1904 ruby: DoS vulnerability in BigDecimal</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140008" comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140009" comment="ruby-ri is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140004" comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140005" comment="ruby-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140010" comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140011" comment="ruby-mode is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140018" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140019" comment="ruby-tcltk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140012" comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140013" comment="ruby-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140006" comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140007" comment="ruby-irb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140014" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140015" comment="ruby-rdoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140002" comment="ruby is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140003" comment="ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140016" comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140017" comment="ruby-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140031" comment="irb is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140032" comment="irb is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140025" comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140026" comment="ruby-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140023" comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140024" comment="ruby-mode is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140033" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140034" comment="ruby-tcltk is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140029" comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140030" comment="ruby-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140021" comment="ruby is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140022" comment="ruby is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091140027" comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091140028" comment="ruby-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091148" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1148: httpd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1148-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1148.html" />
          <reference source="CVE" ref_id="CVE-2009-1890" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1890.html" />
          <reference source="CVE" ref_id="CVE-2009-1891" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1891.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A denial of service flaw was found in the Apache mod_proxy module when it
was used as a reverse proxy. A remote attacker could use this flaw to force
a proxy process to consume large amounts of CPU time. (CVE-2009-1890)

A denial of service flaw was found in the Apache mod_deflate module. This
module continued to compress large files until compression was complete,
even if the network connection that requested the content was closed before
compression completed. This would cause mod_deflate to consume large
amounts of CPU if mod_deflate was enabled for a large file. (CVE-2009-1891)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-09" />
        <updated date="2009-07-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1890.html">CVE-2009-1890</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1891.html">CVE-2009-1891</cve>
                <bugzilla href="http://bugzilla.redhat.com/509125" id="509125">CVE-2009-1891 httpd: possible temporary DoS (CPU consumption) in mod_deflate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509375" id="509375">CVE-2009-1890 httpd: mod_proxy reverse proxy DoS (infinite loop)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091148004" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075005" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091148008" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075007" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091148006" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075009" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091148002" comment="httpd is earlier than 0:2.2.3-22.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091154" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1154: dhcp security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1154-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1154.html" />
          <reference source="CVE" ref_id="CVE-2009-0692" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0692.html" />
          <reference source="CVE" ref_id="CVE-2009-1893" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1893.html" />
    
    <description>The Dynamic Host Configuration Protocol (DHCP) is a protocol that allows
individual devices on an IP network to get their own network configuration
information, including an IP address, a subnet mask, and a broadcast
address.

The Mandriva Linux Engineering Team discovered a stack-based buffer
overflow flaw in the ISC DHCP client. If the DHCP client were to receive a
malicious DHCP response, it could crash or execute arbitrary code with the
permissions of the client (root). (CVE-2009-0692)

An insecure temporary file use flaw was discovered in the DHCP daemon's
init script ("/etc/init.d/dhcpd"). A local attacker could use this flaw to
overwrite an arbitrary file with the output of the "dhcpd -t" command via
a symbolic link attack, if a system administrator executed the DHCP init
script with the "configtest", "restart", or "reload" option.
(CVE-2009-1893)

Users of DHCP should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-14" />
        <updated date="2009-07-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0692.html">CVE-2009-0692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1893.html">CVE-2009-1893</cve>
                <bugzilla href="http://bugzilla.redhat.com/507717" id="507717">CVE-2009-0692 dhclient: stack overflow leads to arbitrary code execution as root</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510024" id="510024">CVE-2009-1893 dhcp: insecure temporary file use in the dhcpd init script</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091154006" comment="dhclient is earlier than 7:3.0.1-10.2_EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091136007" comment="dhclient is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091154004" comment="dhcp-devel is earlier than 7:3.0.1-10.2_EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091136005" comment="dhcp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091154002" comment="dhcp is earlier than 7:3.0.1-10.2_EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091136003" comment="dhcp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091159" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1159: libtiff security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1159-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1159.html" />
          <reference source="CVE" ref_id="CVE-2009-2285" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2285.html" />
          <reference source="CVE" ref_id="CVE-2009-2347" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2347.html" />
    
    <description>The libtiff packages contain a library of functions for manipulating Tagged
Image File Format (TIFF) files.

Several integer overflow flaws, leading to heap-based buffer overflows,
were found in various libtiff color space conversion tools. An attacker
could create a specially-crafted TIFF file, which once opened by an
unsuspecting user, would cause the conversion tool to crash or,
potentially, execute arbitrary code with the privileges of the user running
the tool. (CVE-2009-2347)

A buffer underwrite flaw was found in libtiff's Lempel-Ziv-Welch (LZW)
compression algorithm decoder. An attacker could create a specially-crafted
LZW-encoded TIFF file, which once opened by an unsuspecting user, would
cause an application linked with libtiff to access an out-of-bounds memory
location, leading to a denial of service (application crash).
(CVE-2009-2285)

The CVE-2009-2347 flaws were discovered by Tielei Wang from ICST-ERCIS,
Peking University.

All libtiff users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
all applications linked with the libtiff library (such as Konqueror) must
be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-16" />
        <updated date="2009-07-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2285.html">CVE-2009-2285</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2347.html">CVE-2009-2347</cve>
                <bugzilla href="http://bugzilla.redhat.com/507465" id="507465">CVE-2009-2285 libtiff: LZWDecodeCompat underflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510041" id="510041">CVE-2009-2347 libtiff: integer overflows in various inter-color spaces conversion tools (crash, ACE)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091159002" comment="libtiff is earlier than 0:3.8.2-7.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091159003" comment="libtiff is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091159004" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091159005" comment="libtiff-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091159007" comment="libtiff is earlier than 0:3.5.7-33.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091159008" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091159009" comment="libtiff-devel is earlier than 0:3.5.7-33.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091159010" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091159012" comment="libtiff is earlier than 0:3.6.1-12.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091159008" comment="libtiff is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091159013" comment="libtiff-devel is earlier than 0:3.6.1-12.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091159010" comment="libtiff-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091162" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1162: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1162-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1162.html" />
          <reference source="CVE" ref_id="CVE-2009-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2462.html" />
          <reference source="CVE" ref_id="CVE-2009-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2463.html" />
          <reference source="CVE" ref_id="CVE-2009-2464" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2464.html" />
          <reference source="CVE" ref_id="CVE-2009-2465" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2465.html" />
          <reference source="CVE" ref_id="CVE-2009-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2466.html" />
          <reference source="CVE" ref_id="CVE-2009-2467" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2467.html" />
          <reference source="CVE" ref_id="CVE-2009-2469" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2469.html" />
          <reference source="CVE" ref_id="CVE-2009-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2470.html" />
          <reference source="CVE" ref_id="CVE-2009-2471" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2471.html" />
          <reference source="CVE" ref_id="CVE-2009-2472" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2472.html" />
          <reference source="CVE" ref_id="CVE-2009-2664" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2664.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466,
CVE-2009-2467, CVE-2009-2469, CVE-2009-2471)

Several flaws were found in the way Firefox handles malformed JavaScript
code. A website containing malicious content could launch a cross-site
scripting (XSS) attack or execute arbitrary JavaScript with the permissions
of another website. (CVE-2009-2472)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.12. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.12, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-21" />
        <updated date="2009-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2462.html">CVE-2009-2462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2463.html">CVE-2009-2463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2464.html">CVE-2009-2464</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2465.html">CVE-2009-2465</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2466.html">CVE-2009-2466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2467.html">CVE-2009-2467</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2469.html">CVE-2009-2469</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2470.html">CVE-2009-2470</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2471.html">CVE-2009-2471</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2472.html">CVE-2009-2472</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2664.html">CVE-2009-2664</cve>
                <bugzilla href="http://bugzilla.redhat.com/512128" id="512128">CVE-2009-2462 Mozilla Browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512131" id="512131">CVE-2009-2463 Mozilla Base64 decoding crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512133" id="512133">CVE-2009-2464 Mozilla crash with multiple RDFs in XUL tree</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512135" id="512135">CVE-2009-2465 Mozilla double frame construction crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512136" id="512136">CVE-2009-2466 Mozilla JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512137" id="512137">CVE-2009-2467 Mozilla remote code execution during Flash player unloading</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512142" id="512142">CVE-2009-2469 Mozilla remote code execution using watch and __defineSetter__ on SVG element</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512146" id="512146">CVE-2009-2471 Mozilla setTimeout loses XPCNativeWrappers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512147" id="512147">CVE-2009-2472 Mozilla multiple cross origin wrapper bypasses</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091162006" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091162002" comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091162004" comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091162008" comment="firefox is earlier than 0:3.0.12-1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091162011" comment="firefox is earlier than 0:3.0.12-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091163" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1163: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1163-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1163.html" />
          <reference source="CVE" ref_id="CVE-2009-2462" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2462.html" />
          <reference source="CVE" ref_id="CVE-2009-2463" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2463.html" />
          <reference source="CVE" ref_id="CVE-2009-2466" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2466.html" />
          <reference source="CVE" ref_id="CVE-2009-2470" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2470.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-2462, CVE-2009-2463, CVE-2009-2466)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-21" />
        <updated date="2009-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2462.html">CVE-2009-2462</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2463.html">CVE-2009-2463</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2466.html">CVE-2009-2466</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2470.html">CVE-2009-2470</cve>
                <bugzilla href="http://bugzilla.redhat.com/512128" id="512128">CVE-2009-2462 Mozilla Browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512131" id="512131">CVE-2009-2463 Mozilla Base64 decoding crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512136" id="512136">CVE-2009-2466 Mozilla JavaScript engine crashes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163020" comment="seamonkey-nspr is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163016" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163004" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163006" comment="seamonkey-mail is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163002" comment="seamonkey is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163018" comment="seamonkey-devel is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163014" comment="seamonkey-nss is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163010" comment="seamonkey-chat is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163008" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163012" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.40.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163026" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-45.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163025" comment="seamonkey-mail is earlier than 0:1.0.9-45.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163023" comment="seamonkey is earlier than 0:1.0.9-45.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163028" comment="seamonkey-devel is earlier than 0:1.0.9-45.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163024" comment="seamonkey-chat is earlier than 0:1.0.9-45.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091163027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-45.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091164" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1164: tomcat security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1164-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1164.html" />
          <reference source="CVE" ref_id="CVE-2007-5333" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5333.html" />
          <reference source="CVE" ref_id="CVE-2008-5515" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5515.html" />
          <reference source="CVE" ref_id="CVE-2009-0033" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0033.html" />
          <reference source="CVE" ref_id="CVE-2009-0580" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0580.html" />
          <reference source="CVE" ref_id="CVE-2009-0781" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0781.html" />
          <reference source="CVE" ref_id="CVE-2009-0783" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0783.html" />
    
    <description>Apache Tomcat is a servlet container for the Java Servlet and JavaServer
Pages (JSP) technologies.

It was discovered that the Red Hat Security Advisory RHSA-2007:0871 did not
address all possible flaws in the way Tomcat handles certain characters and
character sequences in cookie values. A remote attacker could use this flaw
to obtain sensitive information, such as session IDs, and then use this
information for session hijacking attacks. (CVE-2007-5333)

Note: The fix for the CVE-2007-5333 flaw changes the default cookie
processing behavior: with this update, version 0 cookies that contain
values that must be quoted to be valid are automatically changed to version
1 cookies. To reactivate the previous, but insecure behavior, add the
following entry to the "/etc/tomcat5/catalina.properties" file:

org.apache.tomcat.util.http.ServerCookie.VERSION_SWITCH=false

It was discovered that request dispatchers did not properly normalize user
requests that have trailing query strings, allowing remote attackers to
send specially-crafted requests that would cause an information leak.
(CVE-2008-5515)

A flaw was found in the way the Tomcat AJP (Apache JServ Protocol)
connector processes AJP connections. An attacker could use this flaw to
send specially-crafted requests that would cause a temporary denial of
service. (CVE-2009-0033)

It was discovered that the error checking methods of certain authentication
classes did not have sufficient error checking, allowing remote attackers
to enumerate (via brute force methods) usernames registered with
applications running on Tomcat when FORM-based authentication was used.
(CVE-2009-0580)

A cross-site scripting (XSS) flaw was found in the examples calendar
application. With some web browsers, remote attackers could use this flaw
to inject arbitrary web script or HTML via the "time" parameter.
(CVE-2009-0781)

It was discovered that web applications containing their own XML parsers
could replace the XML parser Tomcat uses to parse configuration files. A
malicious web application running on a Tomcat instance could read or,
potentially, modify the configuration and XML-based data of other web
applications deployed on the same Tomcat instance. (CVE-2009-0783)

Users of Tomcat should upgrade to these updated packages, which contain
backported patches to resolve these issues. Tomcat must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-21" />
        <updated date="2009-07-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5333.html">CVE-2007-5333</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5515.html">CVE-2008-5515</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0033.html">CVE-2009-0033</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0580.html">CVE-2009-0580</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0781.html">CVE-2009-0781</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0783.html">CVE-2009-0783</cve>
                <bugzilla href="http://bugzilla.redhat.com/427766" id="427766">CVE-2007-5333 Improve cookie parsing for tomcat5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489028" id="489028">CVE-2009-0781 tomcat: XSS in Apache Tomcat calendar application</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493381" id="493381">CVE-2009-0033 tomcat6 Denial-Of-Service with AJP connection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503978" id="503978">CVE-2009-0580 tomcat6 Information disclosure in authentication classes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504153" id="504153">CVE-2009-0783 tomcat XML parser information disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504753" id="504753">CVE-2008-5515 tomcat request dispatcher information disclosure vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164014" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164015" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164004" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164005" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164022" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164023" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164008" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164009" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164012" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164013" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164018" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164019" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164016" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164017" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164020" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164021" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164010" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164011" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164006" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164007" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091164002" comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091164003" comment="tomcat5 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091176" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1176: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1176-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1176.html" />
          <reference source="CVE" ref_id="CVE-2007-2052" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2052.html" />
          <reference source="CVE" ref_id="CVE-2007-4965" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4965.html" />
          <reference source="CVE" ref_id="CVE-2008-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1721.html" />
          <reference source="CVE" ref_id="CVE-2008-1887" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1887.html" />
          <reference source="CVE" ref_id="CVE-2008-2315" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2315.html" />
          <reference source="CVE" ref_id="CVE-2008-3142" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3142.html" />
          <reference source="CVE" ref_id="CVE-2008-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3143.html" />
          <reference source="CVE" ref_id="CVE-2008-3144" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3144.html" />
          <reference source="CVE" ref_id="CVE-2008-4864" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4864.html" />
          <reference source="CVE" ref_id="CVE-2008-5031" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5031.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

When the assert() system call was disabled, an input sanitization flaw was
revealed in the Python string object implementation that led to a buffer
overflow. The missing check for negative size values meant the Python
memory allocator could allocate less memory than expected. This could
result in arbitrary code execution with the Python interpreter's
privileges. (CVE-2008-1887)

Multiple buffer and integer overflow flaws were found in the Python Unicode
string processing and in the Python Unicode and string object
implementations. An attacker could use these flaws to cause a denial of
service (Python application crash). (CVE-2008-3142, CVE-2008-5031)

Multiple integer overflow flaws were found in the Python imageop module. If
a Python application used the imageop module to process untrusted images,
it could cause the application to disclose sensitive information, crash or,
potentially, execute arbitrary code with the Python interpreter's
privileges. (CVE-2007-4965, CVE-2008-4864)

Multiple integer underflow and overflow flaws were found in the Python
snprintf() wrapper implementation. An attacker could use these flaws to
cause a denial of service (memory corruption). (CVE-2008-3144)

Multiple integer overflow flaws were found in various Python modules. An
attacker could use these flaws to cause a denial of service (Python
application crash). (CVE-2008-2315, CVE-2008-3143)

An integer signedness error, leading to a buffer overflow, was found
in the Python zlib extension module. If a Python application requested
the negative byte count be flushed for a decompression stream, it could
cause the application to crash or, potentially, execute arbitrary code
with the Python interpreter's privileges. (CVE-2008-1721)

A flaw was discovered in the strxfrm() function of the Python locale
module. Strings generated by this function were not properly
NULL-terminated, which could possibly cause disclosure of data stored in
the memory of a Python application using this function. (CVE-2007-2052)

Red Hat would like to thank David Remahl of the Apple Product Security team
for responsibly reporting the CVE-2008-2315 issue.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-27" />
        <updated date="2009-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2052.html">CVE-2007-2052</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4965.html">CVE-2007-4965</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1721.html">CVE-2008-1721</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1887.html">CVE-2008-1887</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2315.html">CVE-2008-2315</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3142.html">CVE-2008-3142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3143.html">CVE-2008-3143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3144.html">CVE-2008-3144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4864.html">CVE-2008-4864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5031.html">CVE-2008-5031</cve>
                <bugzilla href="http://bugzilla.redhat.com/235093" id="235093">CVE-2007-2052 python off-by-one locale.strxfrm() (possible memory disclosure)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/295971" id="295971">CVE-2007-4965 python imageop module heap corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442005" id="442005">CVE-2008-1721 python: integer signedness error in the zlib extension module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443810" id="443810">CVE-2008-1887 python: PyString_FromStringAndSize does not check for negative size values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454990" id="454990">CVE-2008-3142 python: Multiple buffer overflows in unicode processing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455008" id="455008">CVE-2008-2315 python: Multiple integer overflows in python core</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455013" id="455013">CVE-2008-3143 python: Multiple integer overflows discovered by Google</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455018" id="455018">CVE-2008-3144 python: Potential integer underflow and overflow in the PyOS_vsnprintf C API function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469656" id="469656">CVE-2008-4864 python: imageop module multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470915" id="470915">CVE-2008-5031 python: stringobject, unicodeobject integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091176004" comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091176005" comment="python-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091176006" comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091176007" comment="tkinter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091176002" comment="python is earlier than 0:2.4.3-24.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091176003" comment="python is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091176008" comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091176009" comment="python-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091177" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1177: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1177-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1177.html" />
          <reference source="CVE" ref_id="CVE-2008-1679" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1679.html" />
          <reference source="CVE" ref_id="CVE-2008-1721" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1721.html" />
          <reference source="CVE" ref_id="CVE-2008-1887" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1887.html" />
          <reference source="CVE" ref_id="CVE-2008-2315" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2315.html" />
          <reference source="CVE" ref_id="CVE-2008-3142" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3142.html" />
          <reference source="CVE" ref_id="CVE-2008-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3143.html" />
          <reference source="CVE" ref_id="CVE-2008-3144" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3144.html" />
          <reference source="CVE" ref_id="CVE-2008-4864" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4864.html" />
          <reference source="CVE" ref_id="CVE-2008-5031" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5031.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

When the assert() system call was disabled, an input sanitization flaw was
revealed in the Python string object implementation that led to a buffer
overflow. The missing check for negative size values meant the Python
memory allocator could allocate less memory than expected. This could
result in arbitrary code execution with the Python interpreter's
privileges. (CVE-2008-1887)

Multiple buffer and integer overflow flaws were found in the Python Unicode
string processing and in the Python Unicode and string object
implementations. An attacker could use these flaws to cause a denial of
service (Python application crash). (CVE-2008-3142, CVE-2008-5031)

Multiple integer overflow flaws were found in the Python imageop module. If
a Python application used the imageop module to process untrusted images,
it could cause the application to crash or, potentially, execute arbitrary
code with the Python interpreter's privileges. (CVE-2008-1679,
CVE-2008-4864)

Multiple integer underflow and overflow flaws were found in the Python
snprintf() wrapper implementation. An attacker could use these flaws to
cause a denial of service (memory corruption). (CVE-2008-3144)

Multiple integer overflow flaws were found in various Python modules. An
attacker could use these flaws to cause a denial of service (Python
application crash). (CVE-2008-2315, CVE-2008-3143)

An integer signedness error, leading to a buffer overflow, was found
in the Python zlib extension module. If a Python application requested
the negative byte count be flushed for a decompression stream, it could
cause the application to crash or, potentially, execute arbitrary code
with the Python interpreter's privileges. (CVE-2008-1721)

Red Hat would like to thank David Remahl of the Apple Product Security team
for responsibly reporting the CVE-2008-1679 and CVE-2008-2315 issues.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-27" />
        <updated date="2009-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1679.html">CVE-2008-1679</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1721.html">CVE-2008-1721</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1887.html">CVE-2008-1887</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2315.html">CVE-2008-2315</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3142.html">CVE-2008-3142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3143.html">CVE-2008-3143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3144.html">CVE-2008-3144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4864.html">CVE-2008-4864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5031.html">CVE-2008-5031</cve>
                <bugzilla href="http://bugzilla.redhat.com/441306" id="441306">CVE-2008-1679 python: imageop module integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442005" id="442005">CVE-2008-1721 python: integer signedness error in the zlib extension module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443810" id="443810">CVE-2008-1887 python: PyString_FromStringAndSize does not check for negative size values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454990" id="454990">CVE-2008-3142 python: Multiple buffer overflows in unicode processing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455008" id="455008">CVE-2008-2315 python: Multiple integer overflows in python core</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455013" id="455013">CVE-2008-3143 python: Multiple integer overflows discovered by Google</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455018" id="455018">CVE-2008-3144 python: Potential integer underflow and overflow in the PyOS_vsnprintf C API function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469656" id="469656">CVE-2008-4864 python: imageop module multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470915" id="470915">CVE-2008-5031 python: stringobject, unicodeobject integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091177006" comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177007" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091177004" comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177005" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091177008" comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177009" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091177002" comment="python is earlier than 0:2.3.4-14.7.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091177010" comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177011" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091178" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1178: python security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1178-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1178.html" />
          <reference source="CVE" ref_id="CVE-2008-1679" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1679.html" />
          <reference source="CVE" ref_id="CVE-2008-1887" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-1887.html" />
          <reference source="CVE" ref_id="CVE-2008-2315" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2315.html" />
          <reference source="CVE" ref_id="CVE-2008-3142" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3142.html" />
          <reference source="CVE" ref_id="CVE-2008-3143" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3143.html" />
          <reference source="CVE" ref_id="CVE-2008-3144" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3144.html" />
          <reference source="CVE" ref_id="CVE-2008-4864" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4864.html" />
          <reference source="CVE" ref_id="CVE-2008-5031" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5031.html" />
    
    <description>Python is an interpreted, interactive, object-oriented programming
language.

When the assert() system call was disabled, an input sanitization flaw was
revealed in the Python string object implementation that led to a buffer
overflow. The missing check for negative size values meant the Python
memory allocator could allocate less memory than expected. This could
result in arbitrary code execution with the Python interpreter's
privileges. (CVE-2008-1887)

Multiple buffer and integer overflow flaws were found in the Python Unicode
string processing and in the Python Unicode and string object
implementations. An attacker could use these flaws to cause a denial of
service (Python application crash). (CVE-2008-3142, CVE-2008-5031)

Multiple integer overflow flaws were found in the Python imageop module. If
a Python application used the imageop module to process untrusted images,
it could cause the application to crash or, potentially, execute arbitrary
code with the Python interpreter's privileges. (CVE-2008-1679,
CVE-2008-4864)

Multiple integer underflow and overflow flaws were found in the Python
snprintf() wrapper implementation. An attacker could use these flaws to
cause a denial of service (memory corruption). (CVE-2008-3144)

Multiple integer overflow flaws were found in various Python modules. An
attacker could use these flaws to cause a denial of service (Python
application crash). (CVE-2008-2315, CVE-2008-3143)

Red Hat would like to thank David Remahl of the Apple Product Security team
for responsibly reporting the CVE-2008-1679 and CVE-2008-2315 issues.

All Python users should upgrade to these updated packages, which contain
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-27" />
        <updated date="2009-07-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1679.html">CVE-2008-1679</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-1887.html">CVE-2008-1887</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2315.html">CVE-2008-2315</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3142.html">CVE-2008-3142</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3143.html">CVE-2008-3143</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3144.html">CVE-2008-3144</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4864.html">CVE-2008-4864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5031.html">CVE-2008-5031</cve>
                <bugzilla href="http://bugzilla.redhat.com/441306" id="441306">CVE-2008-1679 python: imageop module integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443810" id="443810">CVE-2008-1887 python: PyString_FromStringAndSize does not check for negative size values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454990" id="454990">CVE-2008-3142 python: Multiple buffer overflows in unicode processing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455008" id="455008">CVE-2008-2315 python: Multiple integer overflows in python core</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455013" id="455013">CVE-2008-3143 python: Multiple integer overflows discovered by Google</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455018" id="455018">CVE-2008-3144 python: Potential integer underflow and overflow in the PyOS_vsnprintf C API function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469656" id="469656">CVE-2008-4864 python: imageop module multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470915" id="470915">CVE-2008-5031 python: stringobject, unicodeobject integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091178008" comment="python-devel is earlier than 0:2.2.3-6.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177007" comment="python-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091178010" comment="python-docs is earlier than 0:2.2.3-6.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177005" comment="python-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091178004" comment="tkinter is earlier than 0:2.2.3-6.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177009" comment="tkinter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091178002" comment="python is earlier than 0:2.2.3-6.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177003" comment="python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091178006" comment="python-tools is earlier than 0:2.2.3-6.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091177011" comment="python-tools is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091179" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1179: bind security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1179-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1179.html" />
          <reference source="CVE" ref_id="CVE-2009-0696" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0696.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handles dynamic update message packets
containing the "ANY" record type. A remote attacker could use this flaw to
send a specially-crafted dynamic update packet that could cause named to
exit with an assertion failure. (CVE-2009-0696)

Note: even if named is not configured for dynamic updates, receiving such
a specially-crafted dynamic update packet could still cause named to exit
unexpectedly.

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-29" />
        <updated date="2009-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0696.html">CVE-2009-0696</cve>
                <bugzilla href="http://bugzilla.redhat.com/514292" id="514292">CVE-2009-0696 bind: DoS (assertion failure) via nsupdate packets</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179014" comment="bind-libbind-devel is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020005" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179012" comment="bind-utils is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020011" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179010" comment="bind-chroot is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020009" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179004" comment="bind-devel is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020007" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179006" comment="bind-sdb is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020017" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179002" comment="bind is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179016" comment="bind-libs is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020013" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091179008" comment="caching-nameserver is earlier than 30:9.3.4-10.P1.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020015" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091180" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1180: bind security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1180-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1180.html" />
          <reference source="CVE" ref_id="CVE-2009-0696" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0696.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handles dynamic update message packets
containing the "ANY" record type. A remote attacker could use this flaw to
send a specially-crafted dynamic update packet that could cause named to
exit with an assertion failure. (CVE-2009-0696)

Note: even if named is not configured for dynamic updates, receiving such
a specially-crafted dynamic update packet could still cause named to exit
unexpectedly.

This update also fixes the following bug:

* when running on a system receiving a large number of (greater than 4,000)
DNS requests per second, the named DNS nameserver became unresponsive, and
the named service had to be restarted in order for it to continue serving
requests. This was caused by a deadlock occurring between two threads that
led to the inability of named to continue to service requests. This
deadlock has been resolved with these updated packages so that named no
longer becomes unresponsive under heavy load. (BZ#512668)

All BIND users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-29" />
        <updated date="2009-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0696.html">CVE-2009-0696</cve>
                <bugzilla href="http://bugzilla.redhat.com/512668" id="512668">bind gets hung with 4000 accesses / sec</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514292" id="514292">CVE-2009-0696 bind: DoS (assertion failure) via nsupdate packets</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091180010" comment="bind-chroot is earlier than 20:9.2.4-30.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020028" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091180008" comment="bind-utils is earlier than 20:9.2.4-30.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020022" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091180006" comment="bind-devel is earlier than 20:9.2.4-30.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020024" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091180002" comment="bind is earlier than 20:9.2.4-30.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020020" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091180004" comment="bind-libs is earlier than 20:9.2.4-30.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020026" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091181" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1181: bind security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1181-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1181.html" />
          <reference source="CVE" ref_id="CVE-2009-0696" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0696.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

A flaw was found in the way BIND handles dynamic update message packets
containing the "ANY" record type. A remote attacker could use this flaw to
send a specially-crafted dynamic update packet that could cause named to
exit with an assertion failure. (CVE-2009-0696)

Note: even if named is not configured for dynamic updates, receiving such
a specially-crafted dynamic update packet could still cause named to exit
unexpectedly.

This update also fixes the following bug:

* the following message could have been logged: "internal_accept: fcntl()
failed: Too many open files". With these updated packages, timeout queries
are aborted in order to reduce the number of open UDP sockets, and when the
accept() function returns an EMFILE error value, that situation is now
handled gracefully, thus resolving the issue. (BZ#498164)

All BIND users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-29" />
        <updated date="2009-07-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0696.html">CVE-2009-0696</cve>
                <bugzilla href="http://bugzilla.redhat.com/498164" id="498164">bind-9.2.4-22.el3 and too many open files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514292" id="514292">CVE-2009-0696 bind: DoS (assertion failure) via nsupdate packets</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091181010" comment="bind-devel is earlier than 20:9.2.4-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020024" comment="bind-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091181006" comment="bind-chroot is earlier than 20:9.2.4-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020028" comment="bind-chroot is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091181004" comment="bind-utils is earlier than 20:9.2.4-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020022" comment="bind-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091181002" comment="bind is earlier than 20:9.2.4-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020020" comment="bind is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091181008" comment="bind-libs is earlier than 20:9.2.4-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020026" comment="bind-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091184" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1184: nspr and nss security and bug fix update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1184-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1184.html" />
          <reference source="CVE" ref_id="CVE-2009-2404" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2404.html" />
          <reference source="CVE" ref_id="CVE-2009-2408" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2408.html" />
          <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html" />
    
    <description>Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities. These facilities include threads, thread
synchronization, normal file and network I/O, interval timing, calendar
time, basic memory management (malloc and free), and shared library linking.

Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv2, SSLv3, TLS,
and other security standards.

These updated packages upgrade NSS from the previous version, 3.12.2, to a
prerelease of version 3.12.4. The version of NSPR has also been upgraded
from 4.7.3 to 4.7.4. 

Moxie Marlinspike reported a heap overflow flaw in a regular expression
parser in the NSS library used by browsers such as Mozilla Firefox to match
common names in certificates. A malicious website could present a
carefully-crafted certificate in such a way as to trigger the heap
overflow, leading to a crash or, possibly, arbitrary code execution with
the permissions of the user running the browser. (CVE-2009-2404)

Note: in order to exploit this issue without further user interaction in
Firefox, the carefully-crafted certificate would need to be signed by a
Certificate Authority trusted by Firefox, otherwise Firefox presents the
victim with a warning that the certificate is untrusted. Only if the user
then accepts the certificate will the overflow take place.

Dan Kaminsky discovered flaws in the way browsers such as Firefox handle
NULL characters in a certificate. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
Firefox, the attacker could use the certificate during a man-in-the-middle
attack and potentially confuse Firefox into accepting it by mistake.
(CVE-2009-2408)

Dan Kaminsky found that browsers still accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser. NSS
now disables the use of MD2 and MD4 algorithms inside signatures by
default. (CVE-2009-2409)

These version upgrades also provide a fix for the following bug:

* SSL client authentication failed against an Apache server when it was 
using the mod_nss module and configured for NSSOCSP. On the client side,
the user agent received an error message that referenced "Error Code:
-12271" and stated that establishing an encrypted connection had failed
because the certificate had been rejected by the host.

On the server side, the nss_error_log under /var/log/httpd/ contained the
following message:

[error] Re-negotiation handshake failed: Not accepted by client!?

Also, /var/log/httpd/error_log contained this error:

SSL Library Error: -8071 The OCSP server experienced an internal error

With these updated packages, the dependency problem which caused this
failure has been resolved so that SSL client authentication with an
Apache web server using mod_nss which is configured for NSSOCSP succeeds
as expected. Note that if the presented client certificate is expired,
then access is denied, the user agent is presented with an error message
about the invalid certificate, and the OCSP queries are seen in the OCSP
responder. Also, similar OCSP status verification happens for SSL server
certificates used in Apache upon instance start or restart. (BZ#508027)

All users of nspr and nss are advised to upgrade to these updated packages,
which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-30" />
        <updated date="2009-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2404.html">CVE-2009-2404</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2408.html">CVE-2009-2408</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2409.html">CVE-2009-2409</cve>
                <bugzilla href="http://bugzilla.redhat.com/508027" id="508027">rhcs80beta TPS and mod_nss with NSSOCSP has ssl errors and unable to use agent service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510197" id="510197">CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510251" id="510251">CVE-2009-2408 firefox/nss: doesn't handle NULL in Common Name properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512912" id="512912">CVE-2009-2404 nss regexp heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091184002" comment="nss is earlier than 0:3.12.3.99.3-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256022" comment="nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091184006" comment="nss-tools is earlier than 0:3.12.3.99.3-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256026" comment="nss-tools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091184004" comment="nss-devel is earlier than 0:3.12.3.99.3-1.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256024" comment="nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091184010" comment="nspr-devel is earlier than 0:4.7.4-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091184011" comment="nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091184008" comment="nspr is earlier than 0:4.7.4-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091184009" comment="nspr is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091185" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1185: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1185-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1185.html" />
          <reference source="CVE" ref_id="CVE-2009-2404" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2404.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Moxie Marlinspike reported a heap overflow flaw in a regular expression
parser in the NSS library (provided by SeaMonkey) used to match common
names in certificates. A malicious website could present a
carefully-crafted certificate in such a way as to trigger the heap
overflow, leading to a crash or, possibly, arbitrary code execution with
the permissions of the user running SeaMonkey. (CVE-2009-2404)

Note: in order to exploit this issue without further user interaction, the
carefully-crafted certificate would need to be signed by a Certificate
Authority trusted by SeaMonkey, otherwise SeaMonkey presents the victim
with a warning that the certificate is untrusted. Only if the user then
accepts the certificate will the overflow take place.

All SeaMonkey users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, SeaMonkey must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-30" />
        <updated date="2009-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2404.html">CVE-2009-2404</cve>
                <bugzilla href="http://bugzilla.redhat.com/512912" id="512912">CVE-2009-2404 nss regexp heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185014" comment="seamonkey-nspr is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185016" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185010" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185006" comment="seamonkey-mail is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185002" comment="seamonkey is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185020" comment="seamonkey-devel is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185018" comment="seamonkey-chat is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185012" comment="seamonkey-nss is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185008" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091185004" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.41.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091186" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1186: nspr and nss security, bug fix, and enhancement update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1186-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1186.html" />
          <reference source="CVE" ref_id="CVE-2009-2404" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2404.html" />
          <reference source="CVE" ref_id="CVE-2009-2408" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2408.html" />
          <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html" />
    
    <description>Netscape Portable Runtime (NSPR) provides platform independence for non-GUI
operating system facilities. These facilities include threads, thread
synchronization, normal file and network I/O, interval timing, calendar
time, basic memory management (malloc and free), and shared library linking.

Network Security Services (NSS) is a set of libraries designed to support
the cross-platform development of security-enabled client and server
applications. Applications built with NSS can support SSLv2, SSLv3, TLS,
and other security standards.

These updated packages upgrade NSS from the previous version, 3.12.2, to a
prerelease of version 3.12.4. The version of NSPR has also been upgraded
from 4.7.3 to 4.7.4. 

Moxie Marlinspike reported a heap overflow flaw in a regular expression
parser in the NSS library used by browsers such as Mozilla Firefox to match
common names in certificates. A malicious website could present a
carefully-crafted certificate in such a way as to trigger the heap
overflow, leading to a crash or, possibly, arbitrary code execution with
the permissions of the user running the browser. (CVE-2009-2404)

Note: in order to exploit this issue without further user interaction in
Firefox, the carefully-crafted certificate would need to be signed by a
Certificate Authority trusted by Firefox, otherwise Firefox presents the
victim with a warning that the certificate is untrusted. Only if the user
then accepts the certificate will the overflow take place.

Dan Kaminsky discovered flaws in the way browsers such as Firefox handle
NULL characters in a certificate. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
Firefox, the attacker could use the certificate during a man-in-the-middle
attack and potentially confuse Firefox into accepting it by mistake.
(CVE-2009-2408)

Dan Kaminsky found that browsers still accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser. NSS
now disables the use of MD2 and MD4 algorithms inside signatures by
default. (CVE-2009-2409)

All users of nspr and nss are advised to upgrade to these updated packages,
which resolve these issues and add an enhancement.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-30" />
        <updated date="2009-07-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2404.html">CVE-2009-2404</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2408.html">CVE-2009-2408</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2409.html">CVE-2009-2409</cve>
                <bugzilla href="http://bugzilla.redhat.com/510197" id="510197">CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510251" id="510251">CVE-2009-2408 firefox/nss: doesn't handle NULL in Common Name properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512912" id="512912">CVE-2009-2404 nss regexp heap overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091186004" comment="nspr-devel is earlier than 0:4.7.4-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091186005" comment="nspr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091186002" comment="nspr is earlier than 0:4.7.4-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091186003" comment="nspr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091186006" comment="nss is earlier than 0:3.12.3.99.3-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256011" comment="nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091186008" comment="nss-tools is earlier than 0:3.12.3.99.3-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256015" comment="nss-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091186012" comment="nss-pkcs11-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256013" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091186010" comment="nss-devel is earlier than 0:3.12.3.99.3-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256017" comment="nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091188" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1188: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1188-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1188.html" />
          <reference source="CVE" ref_id="CVE-2009-1862" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1862.html" />
          <reference source="CVE" ref_id="CVE-2009-1863" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1863.html" />
          <reference source="CVE" ref_id="CVE-2009-1864" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1864.html" />
          <reference source="CVE" ref_id="CVE-2009-1865" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1865.html" />
          <reference source="CVE" ref_id="CVE-2009-1866" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1866.html" />
          <reference source="CVE" ref_id="CVE-2009-1867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1867.html" />
          <reference source="CVE" ref_id="CVE-2009-1868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1868.html" />
          <reference source="CVE" ref_id="CVE-2009-1869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1869.html" />
          <reference source="CVE" ref_id="CVE-2009-1870" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1870.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

Multiple security flaws were found in the way Flash Player displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
possibly, execute arbitrary code when the victim loaded a page containing
the specially-crafted SWF content. (CVE-2009-1862, CVE-2009-1863,
CVE-2009-1864, CVE-2009-1865, CVE-2009-1866, CVE-2009-1868, CVE-2009-1869)

A clickjacking flaw was discovered in Flash Player. A specially-crafted
SWF file could trick a user into unintentionally or mistakenly clicking a
link or a dialog. (CVE-2009-1867)

A flaw was found in the Flash Player local sandbox. A specially-crafted
SWF file could cause information disclosure when it was saved to the hard
drive. (CVE-2009-1870)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.0.32.18.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-07-31" />
        <updated date="2009-07-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1862.html">CVE-2009-1862</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1863.html">CVE-2009-1863</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1864.html">CVE-2009-1864</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1865.html">CVE-2009-1865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1866.html">CVE-2009-1866</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1867.html">CVE-2009-1867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1868.html">CVE-2009-1868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1869.html">CVE-2009-1869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1870.html">CVE-2009-1870</cve>
                <bugzilla href="http://bugzilla.redhat.com/513362" id="513362">CVE-2009-1862 acroread, flash-plugin: Remote code execution vulnerability via malicious SWF (Shockwave Flash) content</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514874" id="514874">flash-plugin: multiple code execution flaws (APSB09-10)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514877" id="514877">flash-plugin: multiple information disclosure flaws (APSB09-10)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091188002" comment="flash-plugin is earlier than 0:10.0.32.18-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090332003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091193" version="504" class="patch">
      <metadata>
        <title>RHSA-2009:1193: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1193-03" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1193.html" />
          <reference source="CVE" ref_id="CVE-2007-5966" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-5966.html" />
          <reference source="CVE" ref_id="CVE-2009-1385" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1385.html" />
          <reference source="CVE" ref_id="CVE-2009-1388" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1388.html" />
          <reference source="CVE" ref_id="CVE-2009-1389" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1389.html" />
          <reference source="CVE" ref_id="CVE-2009-1895" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1895.html" />
          <reference source="CVE" ref_id="CVE-2009-2406" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2406.html" />
          <reference source="CVE" ref_id="CVE-2009-2407" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2407.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* the possibility of a timeout value overflow was found in the Linux kernel
high-resolution timers functionality, hrtimers. This could allow a local,
unprivileged user to execute arbitrary code, or cause a denial of service
(kernel panic). (CVE-2007-5966, Important)

* a flaw was found in the Intel PRO/1000 network driver in the Linux
kernel. Frames with sizes near the MTU of an interface may be split across
multiple hardware receive descriptors. Receipt of such a frame could leak
through a validation check, leading to a corruption of the length check. A
remote attacker could use this flaw to send a specially-crafted packet that
would cause a denial of service or code execution. (CVE-2009-1385,
Important)

* Michael Tokarev reported a flaw in the Realtek r8169 Ethernet driver in
the Linux kernel. This driver allowed interfaces using this driver to
receive frames larger than could be handled, which could lead to a remote
denial of service or code execution. (CVE-2009-1389, Important)

* the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags were not cleared when a
setuid or setgid program was executed. A local, unprivileged user could use
this flaw to bypass the mmap_min_addr protection mechanism and perform a
NULL pointer dereference attack, or bypass the Address Space Layout
Randomization (ASLR) security feature. (CVE-2009-1895, Important)

* Ramon de Carvalho Valle reported two flaws in the Linux kernel eCryptfs
implementation. A local attacker with permissions to perform an eCryptfs
mount could modify the metadata of the files in that eCrypfts mount to
cause a buffer overflow, leading to a denial of service or privilege
escalation. (CVE-2009-2406, CVE-2009-2407, Important)

* Konstantin Khlebnikov discovered a race condition in the ptrace
implementation in the Linux kernel. This race condition can occur when the
process tracing and the process being traced participate in a core dump. A
local, unprivileged user could use this flaw to trigger a deadlock,
resulting in a partial denial of service. (CVE-2009-1388, Moderate)

Bug fixes (see References below for a link to more detailed notes):

* possible dom0 crash when a Xen para-virtualized guest was installed while
another para-virtualized guest was rebooting. (BZ#497812)

* no directory removal audit record if the directory and its subtree were
recursively watched by an audit rule. (BZ#507561)

* running "echo 1 > /proc/sys/vm/drop_caches" under high memory load could
cause a kernel panic. (BZ#503692)

* on 32-bit systems, core dumps for some multithreaded applications did not
include all thread information. (BZ#505322)

* a stack buffer used by get_event_name() was too small for nul terminator
sprintf() writes. This could lead to an invalid pointer or kernel panic.
(BZ#506906)

* when using the aic94xx driver, systems with SATA drives may not boot due
to a libsas bug. (BZ#506029)

* Wacom Cintiq 21UX and Intuos stylus buttons were handled incorrectly when
moved away from and back to these tablets. (BZ#508275)

* CPU "soft lockup" messages and possibe system hangs on systems with
certain Broadcom network devices and running the Linux kernel from the
kernel-xen package. (BZ#503689)

* on 64-bit PowerPC, getitimer() failed for programs using the ITIMER_REAL
timer that were also compiled for 64-bit systems. This caused such programs
to abort. (BZ#510018)

* write operations could be blocked even when using O_NONBLOCK. (BZ#510239)

* the "pci=nomsi" option was required for installing and booting Red Hat
Enterprise Linux 5.2 on systems with VIA VT3364 chipsets. (BZ#507529)

* shutting down, destroying, or migrating Xen guests with large amounts of
memory could cause other guests to be temporarily unresponsive. (BZ#512311)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Systems must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-04" />
        <updated date="2009-08-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-5966.html">CVE-2007-5966</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1385.html">CVE-2009-1385</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1388.html">CVE-2009-1388</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1389.html">CVE-2009-1389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1895.html">CVE-2009-1895</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2406.html">CVE-2009-2406</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2407.html">CVE-2009-2407</cve>
                <bugzilla href="http://bugzilla.redhat.com/453135" id="453135">CVE-2007-5966 kernel: non-root can trigger cpu_idle soft lockup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497812" id="497812">RH5.3 x64 RC2 reboots while installing a virtual machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502981" id="502981">CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503689" id="503689">Call trace thrown up when stressing the network with bw_tcp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503692" id="503692">Possible panic when drop_pagecache_sb() and prune_icache() run concurrently.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504263" id="504263">CVE-2009-1388 kernel: do_coredump() vs ptrace_start() deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504726" id="504726">CVE-2009-1389 kernel: r8169: fix crash when large packets are received</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505322" id="505322">[Reg][RHEL5.3]  Multi-threaded application dumps a core with wrong thread information</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506029" id="506029">With Red Hat errata 128.1.6 installed system hangs with SATA drives installed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506906" id="506906">kernel: TPM: get_event_name stack corruption [rhel-5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507529" id="507529">disable MSI on VIA VT3364 chipsets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507561" id="507561">Removal of directory doesn't produce audit record if rule is recursive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508275" id="508275">Wacom driver with Intuos tablet does not report button press after a proximity leave/re-enter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510018" id="510018">setitimer(ITIMER_REAL, ...) failing in 64bit enviroment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510239" id="510239">[5.3]Write operation with O_NONBLOCK flag to TTY terminal is blocked</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511171" id="511171">CVE-2009-1895 kernel: personality: fix PER_CLEAR_ON_SETID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512311" id="512311">A Shut down of a 32GB domU's  freezes other domU's for several seconds</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512861" id="512861">CVE-2009-2406 kernel: ecryptfs stack overflow in parse_tag_11_packet()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512885" id="512885">CVE-2009-2407 kernel: ecryptfs heap overflow in parse_tag_3_packet()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:rhel_eus</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193004" comment="kernel-headers is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193002" comment="kernel is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193024" comment="kernel-doc is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193020" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193008" comment="kernel-devel is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193012" comment="kernel-debug is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193016" comment="kernel-kdump is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193014" comment="kernel-xen-devel is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193010" comment="kernel-debug-devel is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193022" comment="kernel-PAE is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193018" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091193006" comment="kernel-xen is earlier than 0:2.6.18-128.4.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091198" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1198: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1198-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1198.html" />
          <reference source="CVE" ref_id="CVE-2009-1093" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1093.html" />
          <reference source="CVE" ref_id="CVE-2009-1094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1094.html" />
          <reference source="CVE" ref_id="CVE-2009-1095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1095.html" />
          <reference source="CVE" ref_id="CVE-2009-1096" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1096.html" />
          <reference source="CVE" ref_id="CVE-2009-1097" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1097.html" />
          <reference source="CVE" ref_id="CVE-2009-1098" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1098.html" />
          <reference source="CVE" ref_id="CVE-2009-1099" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1099.html" />
          <reference source="CVE" ref_id="CVE-2009-1100" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1100.html" />
          <reference source="CVE" ref_id="CVE-2009-1101" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1101.html" />
          <reference source="CVE" ref_id="CVE-2009-1103" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1103.html" />
          <reference source="CVE" ref_id="CVE-2009-1104" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1104.html" />
          <reference source="CVE" ref_id="CVE-2009-1105" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1105.html" />
          <reference source="CVE" ref_id="CVE-2009-1106" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1106.html" />
          <reference source="CVE" ref_id="CVE-2009-1107" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1107.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099, CVE-2009-1100,
CVE-2009-1101, CVE-2009-1103, CVE-2009-1104, CVE-2009-1105, CVE-2009-1106,
CVE-2009-1107)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR5 Java release. All running instances
of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-06" />
        <updated date="2009-08-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1093.html">CVE-2009-1093</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1094.html">CVE-2009-1094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1095.html">CVE-2009-1095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1096.html">CVE-2009-1096</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1097.html">CVE-2009-1097</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1098.html">CVE-2009-1098</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1099.html">CVE-2009-1099</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1100.html">CVE-2009-1100</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1101.html">CVE-2009-1101</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1103.html">CVE-2009-1103</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1104.html">CVE-2009-1104</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1105.html">CVE-2009-1105</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1106.html">CVE-2009-1106</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1107.html">CVE-2009-1107</cve>
                <bugzilla href="http://bugzilla.redhat.com/490166" id="490166">CVE-2009-1101 OpenJDK JAX-WS service endpoint remote Denial-of-Service (6630639)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490167" id="490167">CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service (6717680)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490168" id="490168">CVE-2009-1094 OpenJDK  LDAP client remote code execution (6737315)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490169" id="490169">CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490174" id="490174">CVE-2009-1097 OpenJDK PNG processing buffer overflow vulnerability (6804996)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490178" id="490178">CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability (6804998)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492302" id="492302">CVE-2009-1099 OpenJDK: Type1 font processing buffer overflow vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492305" id="492305">CVE-2009-1100 OpenJDK: DoS (disk consumption) via handling of temporary font files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492306" id="492306">CVE-2009-1103 OpenJDK: Files disclosure, arbitrary code execution via "deserializing applets" (6646860)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492308" id="492308">CVE-2009-1104 OpenJDK: Intended access restrictions bypass via LiveConnect (6724331)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492309" id="492309">CVE-2009-1105 OpenJDK: Possibility of trusted applet run in older, vulnerable version of JRE (6706490)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492310" id="492310">CVE-2009-1106 OpenJDK: Improper parsing of crossdomain.xml files (intended access restriction bypass) (6798948)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492312" id="492312">CVE-2009-1107 OpenJDK: Signed applet remote misuse possibility (6782871)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198010" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015011" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198012" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015007" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198008" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198014" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015005" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198004" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015017" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198016" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015013" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091198006" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.5-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015015" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091199" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1199: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1199-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1199.html" />
          <reference source="CVE" ref_id="CVE-2009-2475" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2475.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
          <reference source="CVE" ref_id="CVE-2009-2670" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2670.html" />
          <reference source="CVE" ref_id="CVE-2009-2671" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2671.html" />
          <reference source="CVE" ref_id="CVE-2009-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2672.html" />
          <reference source="CVE" ref_id="CVE-2009-2673" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2673.html" />
          <reference source="CVE" ref_id="CVE-2009-2675" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2675.html" />
          <reference source="CVE" ref_id="CVE-2009-2676" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2676.html" />
          <reference source="CVE" ref_id="CVE-2009-2689" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2689.html" />
          <reference source="CVE" ref_id="CVE-2009-2720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2720.html" />
          <reference source="CVE" ref_id="CVE-2009-2721" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2721.html" />
          <reference source="CVE" ref_id="CVE-2009-2722" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2722.html" />
          <reference source="CVE" ref_id="CVE-2009-2723" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2723.html" />
          <reference source="CVE" ref_id="CVE-2009-2724" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2724.html" />
    
    <description>The Sun 1.5.0 Java release includes the Sun Java 5 Runtime Environment and
the Sun Java 5 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 5 Runtime
Environment and the Sun Java 5 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2009-2475, CVE-2009-2625, CVE-2009-2670, CVE-2009-2671,
CVE-2009-2672, CVE-2009-2673, CVE-2009-2675, CVE-2009-2676, CVE-2009-2689)

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-06" />
        <updated date="2009-08-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2475.html">CVE-2009-2475</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2670.html">CVE-2009-2670</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2671.html">CVE-2009-2671</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2672.html">CVE-2009-2672</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2673.html">CVE-2009-2673</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2675.html">CVE-2009-2675</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2676.html">CVE-2009-2676</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2689.html">CVE-2009-2689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2720.html">CVE-2009-2720</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2721.html">CVE-2009-2721</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2722.html">CVE-2009-2722</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2723.html">CVE-2009-2723</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2724.html">CVE-2009-2724</cve>
                <bugzilla href="http://bugzilla.redhat.com/512896" id="512896">CVE-2009-2670 OpenJDK Untrusted applet System properties access (6738524)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512907" id="512907">CVE-2009-2671 CVE-2009-2672 OpenJDK Proxy mechanism information leaks  (6801071)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512914" id="512914">CVE-2009-2673 OpenJDK proxy mechanism allows non-authorized socket connections  (6801497)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512920" id="512920">CVE-2009-2675 Java Web Start Buffer unpack200 processing integer overflow (6830335)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513215" id="513215">CVE-2009-2475 OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513222" id="513222">CVE-2009-2689 OpenJDK JDK13Services grants unnecessary privileges  (6777448)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515890" id="515890">CVE-2009-2676 JRE applet launcher vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091199012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.20-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091199002" comment="java-1.5.0-sun is earlier than 0:1.5.0.20-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091199006" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.20-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394009" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091199010" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.20-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091199008" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.20-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394005" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091199004" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.20-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394011" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091200" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1200: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1200-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1200.html" />
          <reference source="CVE" ref_id="CVE-2009-0217" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0217.html" />
          <reference source="CVE" ref_id="CVE-2009-2475" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2475.html" />
          <reference source="CVE" ref_id="CVE-2009-2476" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2476.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
          <reference source="CVE" ref_id="CVE-2009-2670" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2670.html" />
          <reference source="CVE" ref_id="CVE-2009-2671" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2671.html" />
          <reference source="CVE" ref_id="CVE-2009-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2672.html" />
          <reference source="CVE" ref_id="CVE-2009-2673" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2673.html" />
          <reference source="CVE" ref_id="CVE-2009-2674" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2674.html" />
          <reference source="CVE" ref_id="CVE-2009-2675" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2675.html" />
          <reference source="CVE" ref_id="CVE-2009-2676" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2676.html" />
          <reference source="CVE" ref_id="CVE-2009-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2690.html" />
          <reference source="CVE" ref_id="CVE-2009-2716" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2716.html" />
          <reference source="CVE" ref_id="CVE-2009-2718" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2718.html" />
          <reference source="CVE" ref_id="CVE-2009-2719" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2719.html" />
          <reference source="CVE" ref_id="CVE-2009-2720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2720.html" />
    
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2009-0217, CVE-2009-2475, CVE-2009-2476, CVE-2009-2625,
CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2674,
CVE-2009-2675, CVE-2009-2676, CVE-2009-2690)

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-06" />
        <updated date="2009-08-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0217.html">CVE-2009-0217</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2475.html">CVE-2009-2475</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2476.html">CVE-2009-2476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2670.html">CVE-2009-2670</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2671.html">CVE-2009-2671</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2672.html">CVE-2009-2672</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2673.html">CVE-2009-2673</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2674.html">CVE-2009-2674</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2675.html">CVE-2009-2675</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2676.html">CVE-2009-2676</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2690.html">CVE-2009-2690</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2716.html">CVE-2009-2716</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2718.html">CVE-2009-2718</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2719.html">CVE-2009-2719</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2720.html">CVE-2009-2720</cve>
                <bugzilla href="http://bugzilla.redhat.com/511915" id="511915">CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512896" id="512896">CVE-2009-2670 OpenJDK Untrusted applet System properties access (6738524)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512907" id="512907">CVE-2009-2671 CVE-2009-2672 OpenJDK Proxy mechanism information leaks  (6801071)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512914" id="512914">CVE-2009-2673 OpenJDK proxy mechanism allows non-authorized socket connections  (6801497)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512915" id="512915">CVE-2009-2674 Java Web Start Buffer JPEG processing integer overflow (6823373)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512920" id="512920">CVE-2009-2675 Java Web Start Buffer unpack200 processing integer overflow (6830335)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513215" id="513215">CVE-2009-2475 OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513220" id="513220">CVE-2009-2476 OpenJDK OpenType checks can be bypassed (6736293)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513223" id="513223">CVE-2009-2690 OpenJDK private variable information disclosure (6777487)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515890" id="515890">CVE-2009-2676 JRE applet launcher vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091200012" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.15-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392007" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091200002" comment="java-1.6.0-sun is earlier than 1:1.6.0.15-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091200004" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.15-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392011" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091200008" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.15-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392005" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091200006" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.15-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392013" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091200010" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.15-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392009" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091201" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1201: java-1.6.0-openjdk security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1201-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1201.html" />
          <reference source="CVE" ref_id="CVE-2009-0217" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0217.html" />
          <reference source="CVE" ref_id="CVE-2009-2475" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2475.html" />
          <reference source="CVE" ref_id="CVE-2009-2476" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2476.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
          <reference source="CVE" ref_id="CVE-2009-2670" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2670.html" />
          <reference source="CVE" ref_id="CVE-2009-2671" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2671.html" />
          <reference source="CVE" ref_id="CVE-2009-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2672.html" />
          <reference source="CVE" ref_id="CVE-2009-2673" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2673.html" />
          <reference source="CVE" ref_id="CVE-2009-2674" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2674.html" />
          <reference source="CVE" ref_id="CVE-2009-2675" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2675.html" />
          <reference source="CVE" ref_id="CVE-2009-2689" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2689.html" />
          <reference source="CVE" ref_id="CVE-2009-2690" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2690.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

A flaw was found in the way the XML Digital Signature implementation in the
JRE handled HMAC-based XML signatures. An attacker could use this flaw to
create a crafted signature that could allow them to bypass authentication,
or trick a user, applet, or application into accepting untrusted content.
(CVE-2009-0217)

Several potential information leaks were found in various mutable static
variables. These could be exploited in application scenarios that execute
untrusted scripting code. (CVE-2009-2475)

It was discovered that OpenType checks can be bypassed. This could allow a
rogue application to bypass access restrictions by acquiring references to
privileged objects through finalizer resurrection. (CVE-2009-2476)

A denial of service flaw was found in the way the JRE processes XML. A
remote attacker could use this flaw to supply crafted XML that would lead
to a denial of service. (CVE-2009-2625)

A flaw was found in the JRE audio system. An untrusted applet or
application could use this flaw to gain read access to restricted System
properties. (CVE-2009-2670)

Two flaws were found in the JRE proxy implementation. An untrusted applet
or application could use these flaws to discover the usernames of users
running applets and applications, or obtain web browser cookies and use
them for session hijacking attacks. (CVE-2009-2671, CVE-2009-2672)

An additional flaw was found in the proxy mechanism implementation. This
flaw allowed an untrusted applet or application to bypass access
restrictions and communicate using non-authorized socket or URL connections
to hosts other than the origin host. (CVE-2009-2673) 

An integer overflow flaw was found in the way the JRE processes JPEG
images. An untrusted application could use this flaw to extend its
privileges, allowing it to read and write local files, as well as to
execute local applications with the privileges of the user running the
application. (CVE-2009-2674)

An integer overflow flaw was found in the JRE unpack200 functionality. An
untrusted applet or application could extend its privileges, allowing it to
read and write local files, as well as to execute local applications with
the privileges of the user running the applet or application. (CVE-2009-2675)

It was discovered that JDK13Services grants unnecessary privileges to
certain object types. This could be misused by an untrusted applet or
application to use otherwise restricted functionality. (CVE-2009-2689)

An information disclosure flaw was found in the way private Java variables
were handled. An untrusted applet or application could use this flaw to
obtain information from variables that would otherwise be private.
(CVE-2009-2690)

Note: The flaws concerning applets in this advisory, CVE-2009-2475,
CVE-2009-2670, CVE-2009-2671, CVE-2009-2672, CVE-2009-2673, CVE-2009-2675,
CVE-2009-2689, and CVE-2009-2690, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

This update also fixes the following bug:

* the EVR in the java-1.6.0-openjdk package as shipped with Red Hat
Enterprise Linux allowed the java-1.6.0-openjdk package from the EPEL
repository to take precedence (appear newer). Users using
java-1.6.0-openjdk from EPEL would not have received security updates since
October 2008. This update prevents the packages from EPEL from taking
precedence. (BZ#499079)

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-06" />
        <updated date="2009-08-06" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0217.html">CVE-2009-0217</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2475.html">CVE-2009-2475</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2476.html">CVE-2009-2476</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2670.html">CVE-2009-2670</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2671.html">CVE-2009-2671</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2672.html">CVE-2009-2672</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2673.html">CVE-2009-2673</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2674.html">CVE-2009-2674</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2675.html">CVE-2009-2675</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2689.html">CVE-2009-2689</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2690.html">CVE-2009-2690</cve>
                <bugzilla href="http://bugzilla.redhat.com/499079" id="499079">Bad EVR</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511915" id="511915">CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512896" id="512896">CVE-2009-2670 OpenJDK Untrusted applet System properties access (6738524)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512907" id="512907">CVE-2009-2671 CVE-2009-2672 OpenJDK Proxy mechanism information leaks  (6801071)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512914" id="512914">CVE-2009-2673 OpenJDK proxy mechanism allows non-authorized socket connections  (6801497)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512915" id="512915">CVE-2009-2674 Java Web Start Buffer JPEG processing integer overflow (6823373)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512920" id="512920">CVE-2009-2675 Java Web Start Buffer unpack200 processing integer overflow (6830335)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513215" id="513215">CVE-2009-2475 OpenJDK information leaks in mutable variables (6588003,6656586,6656610,6656625,6657133,6657619,6657625,6657695,6660049,6660539,6813167)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513220" id="513220">CVE-2009-2476 OpenJDK OpenType checks can be bypassed (6736293)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513222" id="513222">CVE-2009-2689 OpenJDK JDK13Services grants unnecessary privileges  (6777448)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513223" id="513223">CVE-2009-2690 OpenJDK private variable information disclosure (6777487)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091201002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.2.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091201010" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.2.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377009" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091201004" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.2.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091201008" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.2.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377005" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091201006" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.2.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377007" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091203" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1203: subversion security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1203-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1203.html" />
          <reference source="CVE" ref_id="CVE-2009-2411" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2411.html" />
    
    <description>Subversion (SVN) is a concurrent version control system which enables one
or more users to collaborate in developing and maintaining a hierarchy of
files and directories while keeping a history of all changes.

Matt Lewis, of Google, reported multiple heap overflow flaws in Subversion
(server and client) when parsing binary deltas. A malicious user with
commit access to a server could use these flaws to cause a heap overflow on
that server. A malicious server could use these flaws to cause a heap
overflow on a client when it attempts to checkout or update. These heap
overflows can result in a crash or, possibly, arbitrary code execution.
(CVE-2009-2411)

All Subversion users should upgrade to these updated packages, which
contain a backported patch to correct these issues. After installing the
updated packages, the Subversion server must be restarted for the update
to take effect: restart httpd if you are using mod_dav_svn, or restart
svnserve if it is used.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-10" />
        <updated date="2009-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2411.html">CVE-2009-2411</cve>
                <bugzilla href="http://bugzilla.redhat.com/514744" id="514744">CVE-2009-2411 subversion: multiple heap overflow issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203006" comment="subversion-devel is earlier than 0:1.4.2-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203007" comment="subversion-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203002" comment="subversion is earlier than 0:1.4.2-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203003" comment="subversion is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203012" comment="subversion-perl is earlier than 0:1.4.2-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203013" comment="subversion-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203008" comment="subversion-ruby is earlier than 0:1.4.2-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203009" comment="subversion-ruby is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203004" comment="subversion-javahl is earlier than 0:1.4.2-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203005" comment="subversion-javahl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203010" comment="mod_dav_svn is earlier than 0:1.4.2-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203011" comment="mod_dav_svn is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203019" comment="subversion-devel is earlier than 0:1.1.4-3.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203020" comment="subversion-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203015" comment="subversion is earlier than 0:1.1.4-3.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203016" comment="subversion is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203021" comment="subversion-perl is earlier than 0:1.1.4-3.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203022" comment="subversion-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091203017" comment="mod_dav_svn is earlier than 0:1.1.4-3.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091203018" comment="mod_dav_svn is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091204" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1204: apr and apr-util security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1204-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1204.html" />
          <reference source="CVE" ref_id="CVE-2009-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2412.html" />
    
    <description>The Apache Portable Runtime (APR) is a portability library used by the
Apache HTTP Server and other projects. It aims to provide a free library
of C data structures and routines. apr-util is a utility library used with
APR. This library provides additional utility interfaces for APR; including
support for XML parsing, LDAP, database interfaces, URI parsing, and more.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way the Apache Portable Runtime (APR) manages memory pool
and relocatable memory allocations. An attacker could use these flaws to
issue a specially-crafted request for memory allocation, which would lead
to a denial of service (application crash) or, potentially, execute
arbitrary code with the privileges of an application using the APR
libraries. (CVE-2009-2412)

All apr and apr-util users should upgrade to these updated packages, which
contain backported patches to correct these issues. Applications using the
APR libraries, such as httpd, must be restarted for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-10" />
        <updated date="2009-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2412.html">CVE-2009-2412</cve>
                <bugzilla href="http://bugzilla.redhat.com/515698" id="515698">CVE-2009-2412 apr, apr-util: Integer overflows in memory pool (apr) and relocatable memory (apr-util) management</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204004" comment="apr-devel is earlier than 0:1.2.7-11.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091204005" comment="apr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204002" comment="apr is earlier than 0:1.2.7-11.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091204003" comment="apr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204006" comment="apr-docs is earlier than 0:1.2.7-11.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091204007" comment="apr-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204008" comment="apr-util is earlier than 0:1.2.7-7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107003" comment="apr-util is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204012" comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107005" comment="apr-util-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204010" comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107007" comment="apr-util-docs is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204017" comment="apr-devel is earlier than 0:0.9.4-24.9.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091204018" comment="apr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204015" comment="apr is earlier than 0:0.9.4-24.9.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091204016" comment="apr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204019" comment="apr-util is earlier than 0:0.9.4-22.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107010" comment="apr-util is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091204021" comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091107012" comment="apr-util-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091205" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1205: httpd security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1205-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1205.html" />
          <reference source="CVE" ref_id="CVE-2009-1891" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1891.html" />
          <reference source="CVE" ref_id="CVE-2009-2412" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2412.html" />
    
    <description>The Apache HTTP Server is a popular Web server. The httpd package shipped
with Red Hat Enterprise Linux 3 contains embedded copies of the Apache
Portable Runtime (APR) libraries, which provide a free library of C data
structures and routines, and also additional utility interfaces to support
XML parsing, LDAP, database interfaces, URI parsing, and more.

Multiple integer overflow flaws, leading to heap-based buffer overflows,
were found in the way the Apache Portable Runtime (APR) manages memory pool
and relocatable memory allocations. An attacker could use these flaws to
issue a specially-crafted request for memory allocation, which would lead
to a denial of service (application crash) or, potentially, execute
arbitrary code with the privileges of an application using the APR
libraries. (CVE-2009-2412)

A denial of service flaw was found in the Apache mod_deflate module. This
module continued to compress large files until compression was complete,
even if the network connection that requested the content was closed
before compression completed. This would cause mod_deflate to consume
large amounts of CPU if mod_deflate was enabled for a large file.
(CVE-2009-1891)

This update also fixes the following bug:

* in some cases the Content-Length header was dropped from HEAD responses.
This resulted in certain sites not working correctly with mod_proxy, such
as www.windowsupdate.com. (BZ#506016)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-10" />
        <updated date="2009-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1891.html">CVE-2009-1891</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2412.html">CVE-2009-2412</cve>
                <bugzilla href="http://bugzilla.redhat.com/506016" id="506016">windowsupdate.microsoft.com does not work with mod_proxy</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509125" id="509125">CVE-2009-1891 httpd: possible temporary DoS (CPU consumption) in mod_deflate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515698" id="515698">CVE-2009-2412 apr, apr-util: Integer overflows in memory pool (apr) and relocatable memory (apr-util) management</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091205004" comment="httpd-devel is earlier than 0:2.0.46-75.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091205006" comment="mod_ssl is earlier than 0:2.0.46-75.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091205002" comment="httpd is earlier than 0:2.0.46-75.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091206" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1206: libxml and libxml2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1206-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1206.html" />
          <reference source="CVE" ref_id="CVE-2009-2414" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2414.html" />
          <reference source="CVE" ref_id="CVE-2009-2416" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2416.html" />
    
    <description>libxml is a library for parsing and manipulating XML files. A Document Type
Definition (DTD) defines the legal syntax (and also which elements can be
used) for certain types of files, such as XML files.

A stack overflow flaw was found in the way libxml processes the root XML
document element definition in a DTD. A remote attacker could provide a
specially-crafted XML file, which once opened by a local, unsuspecting
user, would lead to denial of service (application crash). (CVE-2009-2414)

Multiple use-after-free flaws were found in the way libxml parses the
Notation and Enumeration attribute types. A remote attacker could provide
a specially-crafted XML file, which once opened by a local, unsuspecting
user, would lead to denial of service (application crash). (CVE-2009-2416)

Users should upgrade to these updated packages, which contain backported
patches to resolve these issues. For Red Hat Enterprise Linux 3, they
contain backported patches for the libxml and libxml2 packages. For Red Hat
Enterprise Linux 4 and 5, they contain backported patches for the libxml2
packages. The desktop must be restarted (log out, then log back in) for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-10" />
        <updated date="2009-08-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2414.html">CVE-2009-2414</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2416.html">CVE-2009-2416</cve>
                <bugzilla href="http://bugzilla.redhat.com/515195" id="515195">CVE-2009-2414 libxml, libxml2, mingw32-libxml2: Stack overflow by parsing root XML element DTD definition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515205" id="515205">CVE-2009-2416 libxml, libxml2, mingw32-libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206002" comment="libxml2 is earlier than 0:2.6.26-2.1.2.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206003" comment="libxml2 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206006" comment="libxml2-devel is earlier than 0:2.6.26-2.1.2.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206007" comment="libxml2-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206004" comment="libxml2-python is earlier than 0:2.6.26-2.1.2.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206005" comment="libxml2-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206011" comment="libxml-devel is earlier than 1:1.8.17-9.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206012" comment="libxml-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206009" comment="libxml is earlier than 1:1.8.17-9.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206010" comment="libxml is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206013" comment="libxml2 is earlier than 0:2.5.10-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206014" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206015" comment="libxml2-devel is earlier than 0:2.5.10-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206016" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206017" comment="libxml2-python is earlier than 0:2.5.10-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206018" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206020" comment="libxml2 is earlier than 0:2.6.16-12.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206014" comment="libxml2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206022" comment="libxml2-devel is earlier than 0:2.6.16-12.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206016" comment="libxml2-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091206021" comment="libxml2-python is earlier than 0:2.6.16-12.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091206018" comment="libxml2-python is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091209" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1209: curl security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1209-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1209.html" />
          <reference source="CVE" ref_id="CVE-2009-2417" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2417.html" />
    
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

Scott Cantor reported that cURL is affected by the previously published
"null prefix attack", caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse cURL into accepting it by mistake. (CVE-2009-2417)

cURL users should upgrade to these updated packages, which contain a
backported patch to correct these issues. All running applications using
libcurl must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-13" />
        <updated date="2009-08-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2417.html">CVE-2009-2417</cve>
                <bugzilla href="http://bugzilla.redhat.com/516181" id="516181">CVE-2009-2417 curl: incorrect verification of SSL certificate with NUL in name</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091209002" comment="curl is earlier than 0:7.15.5-2.1.el5_3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341003" comment="curl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091209004" comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341005" comment="curl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091209007" comment="curl is earlier than 0:7.10.6-10.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341008" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091209009" comment="curl-devel is earlier than 0:7.10.6-10.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341010" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091209012" comment="curl is earlier than 0:7.12.1-11.1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341008" comment="curl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091209013" comment="curl-devel is earlier than 0:7.12.1-11.1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341010" comment="curl-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091211" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1211: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1211-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1211.html" />
          <reference source="CVE" ref_id="CVE-2009-1389" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1389.html" />
          <reference source="CVE" ref_id="CVE-2009-1439" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1439.html" />
          <reference source="CVE" ref_id="CVE-2009-1633" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1633.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* Michael Tokarev reported a flaw in the Realtek r8169 Ethernet driver in
the Linux kernel. This driver allowed interfaces using this driver to
receive frames larger than what could be handled. This could lead to a
remote denial of service or code execution. (CVE-2009-1389, Important)

* a buffer overflow flaw was found in the CIFSTCon() function of the Linux
kernel Common Internet File System (CIFS) implementation. When mounting a
CIFS share, a malicious server could send an overly-long string to the
client, possibly leading to a denial of service or privilege escalation on
the client mounting the CIFS share. (CVE-2009-1439, Important)

* several flaws were found in the way the Linux kernel CIFS implementation
handles Unicode strings. CIFS clients convert Unicode strings sent by a
server to their local character sets, and then write those strings into
memory. If a malicious server sent a long enough string, it could write
past the end of the target memory region and corrupt other memory areas,
possibly leading to a denial of service or privilege escalation on the
client mounting the CIFS share. (CVE-2009-1633, Important)

These updated packages also fix the following bugs:

* when using network bonding in the "balance-tlb" or "balance-alb" mode,
the primary setting for the primary slave device was lost when said
device was brought down (ifdown). Bringing the slave interface back up
(ifup) did not restore the primary setting (the device was not made the
active slave). (BZ#507563)

* a bug in timer_interrupt() may have caused the system time to move up to
two days or more into the future, or to be delayed for several minutes.
This bug only affected Intel 64 and AMD64 systems that have the High
Precision Event Timer (HPET) enabled in the BIOS, and could have caused
problems for applications that require timing to be accurate. (BZ#508835)

* a race condition was resolved in the Linux kernel block layer between
show_partition() and rescan_partitions(). This could have caused a NULL
pointer dereference in show_partition(), leading to a system crash (kernel
panic). This issue was most likely to occur on systems running monitoring
software that regularly scanned hard disk partitions, or from repeatedly
running commands that probe for partition information. (BZ#512310)

* previously, the Stratus memory tracker missed certain modified pages.
With this update, information about the type of page (small page or
huge page) is passed to the Stratus memory tracker, which resolves this
issue. The fix for this issue does not affect systems that do not use
memory tracking. (BZ#513182)

* a bug may have caused a system crash when using the cciss driver, due to
an uninitialized kernel structure. A reported case of this issue occurred
after issuing consecutive SCSI TUR commands (sg_turs sends SCSI
test-unit-ready commands in a loop). (BZ#513189)

* a bug in the SCSI implementation caused "Aborted Command - internal
target failure" errors to be sent to Device-Mapper Multipath, without
retries, resulting in Device-Mapper Multipath marking the path as failed
and making a path group switch. With this update, all errors that return a
sense key in the SCSI mid layer (including "Aborted Command - internal
target failure") are retried. (BZ#514007)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-13" />
        <updated date="2009-08-13" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1389.html">CVE-2009-1389</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1439.html">CVE-2009-1439</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1633.html">CVE-2009-1633</cve>
                <bugzilla href="http://bugzilla.redhat.com/494275" id="494275">CVE-2009-1439 kernel: cifs: memory overwrite when saving nativeFileSystem field during mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496572" id="496572">CVE-2009-1633 kernel: cifs: fix potential buffer overruns when converting unicode strings sent by server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504726" id="504726">CVE-2009-1389 kernel: r8169: fix crash when large packets are received</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507563" id="507563">A bond's preferred primary setting is lost after bringing down and up of the primary slave.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508835" id="508835">[4.6] The system time leaps 2 days 21 hours 41 min future.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512310" id="512310">show_partition() oops when race with rescan_partitions().</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513182" id="513182">Function unmap_hugepage_range passing PMD instead of PTE to ptep_get_and_clear</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513189" id="513189">RHEL4.8: crash in do_cciss_request()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514007" id="514007">Make Aborted Command (internal target failure) retryable at SCSI layer (sense B 44 00)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211002" comment="kernel is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211022" comment="kernel-doc is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211004" comment="kernel-devel is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211010" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211018" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211014" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211006" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211016" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211012" comment="kernel-xenU is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091211008" comment="kernel-smp is earlier than 0:2.6.9-89.0.7.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091218" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1218: pidgin security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1218-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1218.html" />
          <reference source="CVE" ref_id="CVE-2009-2694" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2694.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

Federico Muttis of Core Security Technologies discovered a flaw in Pidgin's
MSN protocol handler. If a user received a malicious MSN message, it was
possible to execute arbitrary code with the permissions of the user running
Pidgin. (CVE-2009-2694)

Note: Users can change their privacy settings to only allow messages from
users on their buddy list to limit the impact of this flaw.

These packages upgrade Pidgin to version 2.5.9. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which resolve
this issue. Pidgin must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-18" />
        <updated date="2009-08-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2694.html">CVE-2009-2694</cve>
                <bugzilla href="http://bugzilla.redhat.com/514957" id="514957">CVE-2009-2694 pidgin: insufficient input validation in msn_slplink_process_msg()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218018" comment="libpurple is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060009" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218010" comment="finch is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060017" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218006" comment="libpurple-perl is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060011" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218002" comment="pidgin is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218016" comment="pidgin-perl is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060013" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218014" comment="finch-devel is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060007" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218008" comment="pidgin-devel is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218004" comment="libpurple-devel is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060005" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218012" comment="libpurple-tcl is earlier than 0:2.5.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060015" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091218021" comment="pidgin is earlier than 0:1.5.1-4.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218039" comment="finch is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060032" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218027" comment="libpurple is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060030" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218025" comment="libpurple-perl is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060038" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218024" comment="pidgin is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218037" comment="pidgin-perl is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060028" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218035" comment="pidgin-devel is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060036" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218033" comment="finch-devel is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060034" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218031" comment="libpurple-devel is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060026" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091218029" comment="libpurple-tcl is earlier than 0:2.5.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060024" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091219" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1219: libvorbis security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1219-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1219.html" />
          <reference source="CVE" ref_id="CVE-2009-2663" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2663.html" />
    
    <description>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

An insufficient input validation flaw was found in the way libvorbis
processes the codec file headers (static mode headers and encoding books)
of the Ogg Vorbis audio file format (Ogg). A remote attacker could provide
a specially-crafted Ogg file that would cause a denial of service (memory
corruption and application crash) or, potentially, execute arbitrary code
with the privileges of an application using the libvorbis library when
opened by a victim. (CVE-2009-2663)

Users of libvorbis should upgrade to these updated packages, which contain
a backported patch to correct this issue. The desktop must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-18" />
        <updated date="2009-08-18" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2663.html">CVE-2009-2663</cve>
                <bugzilla href="http://bugzilla.redhat.com/516259" id="516259">CVE-2009-2663 libvorbis: Improper codec headers processing (DoS, ACE)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091219004" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219005" comment="libvorbis-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091219002" comment="libvorbis is earlier than 1:1.1.2-3.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219003" comment="libvorbis is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091219009" comment="libvorbis-devel is earlier than 1:1.0-11.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091219007" comment="libvorbis is earlier than 1:1.0-11.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091219013" comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091219012" comment="libvorbis is earlier than 1:1.1.0-3.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091222" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1222: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1222-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1222.html" />
          <reference source="CVE" ref_id="CVE-2009-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2692.html" />
          <reference source="CVE" ref_id="CVE-2009-2698" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2698.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This
macro did not initialize the sendpage operation in the proto_ops structure
correctly. A local, unprivileged user could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2692, Important)

* a flaw was found in the udp_sendmsg() implementation in the Linux kernel
when using the MSG_MORE flag on UDP sockets. A local, unprivileged user
could use this flaw to cause a local denial of service or escalate their
privileges. (CVE-2009-2698, Important)

Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the Google
Security Team for responsibly reporting these flaws.

These updated packages also fix the following bug:

* in the dlm code, a socket was allocated in tcp_connect_to_sock(), but was
not freed in the error exit path. This bug led to a memory leak and an
unresponsive system. A reported case of this bug occurred after running
"cman_tool kill -n [nodename]". (BZ#515432)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-24" />
        <updated date="2009-08-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2692.html">CVE-2009-2692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2698.html">CVE-2009-2698</cve>
                <bugzilla href="http://bugzilla.redhat.com/515432" id="515432">dlm_send  socket leak [rhel-5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516949" id="516949">CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/518034" id="518034">CVE-2009-2698 kernel: udp socket NULL ptr dereference</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222004" comment="kernel-headers is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222002" comment="kernel is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222024" comment="kernel-doc is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222022" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222010" comment="kernel-devel is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222012" comment="kernel-debug is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222018" comment="kernel-kdump is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222008" comment="kernel-xen-devel is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222014" comment="kernel-debug-devel is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222020" comment="kernel-PAE is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222016" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091222006" comment="kernel-xen is earlier than 0:2.6.18-128.7.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091223" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1223: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1223-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1223.html" />
          <reference source="CVE" ref_id="CVE-2009-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2692.html" />
          <reference source="CVE" ref_id="CVE-2009-2698" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2698.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This
macro did not initialize the sendpage operation in the proto_ops structure
correctly. A local, unprivileged user could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2692, Important)

* a flaw was found in the udp_sendmsg() implementation in the Linux kernel
when using the MSG_MORE flag on UDP sockets. A local, unprivileged user
could use this flaw to cause a local denial of service or escalate their
privileges. (CVE-2009-2698, Important)

Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the Google
Security Team for responsibly reporting these flaws.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-24" />
        <updated date="2009-08-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2692.html">CVE-2009-2692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2698.html">CVE-2009-2698</cve>
                <bugzilla href="http://bugzilla.redhat.com/516949" id="516949">CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/518034" id="518034">CVE-2009-2698 kernel: udp socket NULL ptr dereference</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223002" comment="kernel is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223022" comment="kernel-doc is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223004" comment="kernel-devel is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223012" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223020" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223010" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223014" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223006" comment="kernel-xenU is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091223016" comment="kernel-smp is earlier than 0:2.6.9-89.0.9.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091232" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1232: gnutls security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1232-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1232.html" />
          <reference source="CVE" ref_id="CVE-2009-2730" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2730.html" />
    
    <description>The GnuTLS library provides support for cryptographic algorithms and for
protocols such as Transport Layer Security (TLS).

A flaw was discovered in the way GnuTLS handles NULL characters in certain
fields of X.509 certificates. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
an application using GnuTLS, the attacker could use the certificate during
a man-in-the-middle attack and potentially confuse the application into
accepting it by mistake. (CVE-2009-2730)

Users of GnuTLS are advised to upgrade to these updated packages, which
contain a backported patch that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-26" />
        <updated date="2009-08-26" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2730.html">CVE-2009-2730</cve>
                <bugzilla href="http://bugzilla.redhat.com/516231" id="516231">CVE-2009-2730 gnutls: incorrect verification of SSL certificate with NUL in name (GNUTLS-SA-2009-4)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091232006" comment="gnutls-devel is earlier than 0:1.4.1-3.el5_3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091232007" comment="gnutls-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091232004" comment="gnutls-utils is earlier than 0:1.4.1-3.el5_3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091232005" comment="gnutls-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091232002" comment="gnutls is earlier than 0:1.4.1-3.el5_3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091232003" comment="gnutls is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091232011" comment="gnutls-devel is earlier than 0:1.0.20-4.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091232012" comment="gnutls-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091232009" comment="gnutls is earlier than 0:1.0.20-4.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091232010" comment="gnutls is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091233" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1233: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1233-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1233.html" />
          <reference source="CVE" ref_id="CVE-2009-2692" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2692.html" />
          <reference source="CVE" ref_id="CVE-2009-2698" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2698.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* a flaw was found in the SOCKOPS_WRAP macro in the Linux kernel. This
macro did not initialize the sendpage operation in the proto_ops structure
correctly. A local, unprivileged user could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2692, Important)

* a flaw was found in the udp_sendmsg() implementation in the Linux kernel
when using the MSG_MORE flag on UDP sockets. A local, unprivileged user
could use this flaw to cause a local denial of service or escalate their
privileges. (CVE-2009-2698, Important)

Red Hat would like to thank Tavis Ormandy and Julien Tinnes of the Google
Security Team for responsibly reporting these flaws.

All Red Hat Enterprise Linux 3 users should upgrade to these updated
packages, which contain backported patches to resolve these issues. The
system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-27" />
        <updated date="2009-08-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2692.html">CVE-2009-2692</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2698.html">CVE-2009-2698</cve>
                <bugzilla href="http://bugzilla.redhat.com/516949" id="516949">CVE-2009-2692 kernel: uninit op in SOCKOPS_WRAP() leads to privesc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/518034" id="518034">CVE-2009-2698 kernel: udp socket NULL ptr dereference</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233006" comment="kernel-source is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233007" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233002" comment="kernel is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233012" comment="kernel-doc is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233018" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233016" comment="kernel-hugemem is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233014" comment="kernel-BOOT is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233004" comment="kernel-smp-unsupported is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233010" comment="kernel-unsupported is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233011" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091233008" comment="kernel-smp is earlier than 0:2.4.21-60.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091236" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1236: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1236-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1236.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
          <reference source="CVE" ref_id="CVE-2009-2670" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2670.html" />
          <reference source="CVE" ref_id="CVE-2009-2671" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2671.html" />
          <reference source="CVE" ref_id="CVE-2009-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2672.html" />
          <reference source="CVE" ref_id="CVE-2009-2673" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2673.html" />
          <reference source="CVE" ref_id="CVE-2009-2675" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2675.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-2625, CVE-2009-2670, CVE-2009-2671,
CVE-2009-2672, CVE-2009-2673, CVE-2009-2675)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR10 Java release. All running instances
of IBM Java must be restarted for this update to take effect.

Note: The packages included in this update are identical to the packages
made available by RHEA-2009:1208 and RHEA-2009:1210 on the 13th of
August 2009. These packages are being reissued as a Red Hat Security
Advisory as they fixed a number of security issues that were not made
public until after those errata were released. Since the packages are
identical, there is no need to install this update if RHEA-2009:1208 or
RHEA-2009:1210 has already been installed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-28" />
        <updated date="2009-08-28" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2670.html">CVE-2009-2670</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2671.html">CVE-2009-2671</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2672.html">CVE-2009-2672</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2673.html">CVE-2009-2673</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2675.html">CVE-2009-2675</cve>
                <bugzilla href="http://bugzilla.redhat.com/512896" id="512896">CVE-2009-2670 OpenJDK Untrusted applet System properties access (6738524)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512907" id="512907">CVE-2009-2671 CVE-2009-2672 OpenJDK Proxy mechanism information leaks  (6801071)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512914" id="512914">CVE-2009-2673 OpenJDK proxy mechanism allows non-authorized socket connections  (6801497)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512920" id="512920">CVE-2009-2675 Java Web Start Buffer unpack200 processing integer overflow (6830335)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236016" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236008" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016009" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236006" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236012" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016017" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236014" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236010" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016011" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091236004" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.10-1jpp.4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016013" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091238" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1238: dnsmasq security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1238-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1238.html" />
          <reference source="CVE" ref_id="CVE-2009-2957" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2957.html" />
          <reference source="CVE" ref_id="CVE-2009-2958" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2958.html" />
    
    <description>Dnsmasq is a lightweight and easy to configure DNS forwarder and DHCP
server.

Core Security Technologies discovered a heap overflow flaw in dnsmasq when
the TFTP service is enabled (the "--enable-tftp" command line option, or by
enabling "enable-tftp" in "/etc/dnsmasq.conf"). If the configured tftp-root
is sufficiently long, and a remote user sends a request that sends a long
file name, dnsmasq could crash or, possibly, execute arbitrary code with
the privileges of the dnsmasq service (usually the unprivileged "nobody"
user). (CVE-2009-2957)

A NULL pointer dereference flaw was discovered in dnsmasq when the TFTP
service is enabled. This flaw could allow a malicious TFTP client to crash
the dnsmasq service. (CVE-2009-2958)

Note: The default tftp-root is "/var/ftpd", which is short enough to make
it difficult to exploit the CVE-2009-2957 issue; if a longer directory name
is used, arbitrary code execution may be possible. As well, the dnsmasq
package distributed by Red Hat does not have TFTP support enabled by
default.

All users of dnsmasq should upgrade to this updated package, which contains
a backported patch to correct these issues. After installing the updated
package, the dnsmasq service must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-08-31" />
        <updated date="2009-08-31" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2957.html">CVE-2009-2957</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2958.html">CVE-2009-2958</cve>
                <bugzilla href="http://bugzilla.redhat.com/519020" id="519020">CVE-2009-2957, CVE-2009-2958 dnsmasq: multiple vulnerabilities in TFTP server</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091238002" comment="dnsmasq is earlier than 0:2.45-1.1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091238003" comment="dnsmasq is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091243" version="504" class="patch">
      <metadata>
        <title>RHSA-2009:1243: Red Hat Enterprise Linux 5.4 kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1243-03" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1243.html" />
          <reference source="CVE" ref_id="CVE-2009-0745" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0745.html" />
          <reference source="CVE" ref_id="CVE-2009-0746" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0746.html" />
          <reference source="CVE" ref_id="CVE-2009-0747" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0747.html" />
          <reference source="CVE" ref_id="CVE-2009-0748" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0748.html" />
          <reference source="CVE" ref_id="CVE-2009-2847" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2847.html" />
          <reference source="CVE" ref_id="CVE-2009-2848" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2848.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

These updated packages fix the following security issues:

* it was discovered that, when executing a new process, the clear_child_tid
pointer in the Linux kernel is not cleared. If this pointer points to a
writable portion of the memory of the new program, the kernel could corrupt
four bytes of memory, possibly leading to a local denial of service or
privilege escalation. (CVE-2009-2848, Important)

* a flaw was found in the way the do_sigaltstack() function in the Linux
kernel copies the stack_t structure to user-space. On 64-bit machines, this
flaw could lead to a four-byte information leak. (CVE-2009-2847, Moderate)

* a flaw was found in the ext4 file system code. A local attacker could use
this flaw to cause a denial of service by performing a resize operation on
a specially-crafted ext4 file system. (CVE-2009-0745, Low)

* multiple flaws were found in the ext4 file system code. A local attacker
could use these flaws to cause a denial of service by mounting a
specially-crafted ext4 file system. (CVE-2009-0746, CVE-2009-0747,
CVE-2009-0748, Low)

These updated packages also include several hundred bug fixes for and
enhancements to the Linux kernel. Space precludes documenting each of these
changes in this advisory and users are directed to the Red Hat Enterprise
Linux 5.4 Release Notes for information on the most significant of these
changes:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.4/html/Release_Notes/

Also, for details concerning every bug fixed in and every enhancement added
to the kernel for this release, see the kernel chapter in the Red Hat
Enterprise Linux 5.4 Technical Notes:

http://www.redhat.com/docs/en-US/Red_Hat_Enterprise_Linux/5.4/html/Technical_Notes/kernel.html

All Red Hat Enterprise Linux 5 users are advised to install these updated
packages, which address these vulnerabilities as well as fixing the bugs
and adding the enhancements noted in the Red Hat Enterprise Linux 5.4
Release Notes and Technical Notes. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0745.html">CVE-2009-0745</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0746.html">CVE-2009-0746</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0747.html">CVE-2009-0747</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0748.html">CVE-2009-0748</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2847.html">CVE-2009-2847</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2848.html">CVE-2009-2848</cve>
                <bugzilla href="http://bugzilla.redhat.com/223947" id="223947">raid10_make_request bug: can't convert block across chunks or bigger than 64k..</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/233801" id="233801">PCI devices disappear in Xen Paravirtual DomU on reboot/reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/240429" id="240429">RHEL5 Kernel crash when specifying mem= or highmem= kernel parameter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/242696" id="242696">Add Filesystem Label to GFS2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244967" id="244967">Frequent path failures during I/O on DM multipath devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/290701" id="290701">pci: MSI/HT problems with some nvidia bridge chips</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/396621" id="396621">Increase timeout for device connection on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/427588" id="427588">[RHEL 5.2]: Tick divider bug when using clocksource=pit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436791" id="436791">Kernel BUG at drivers/scsi/iscsi_tcp.c:387 - invalid opcode: 0000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439898" id="439898">module load option to enable entropy generation from e1000,bnx2 network cards</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443541" id="443541">Online resize2fs error: Invalid argument While trying to add group #15625</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445433" id="445433">A deadlock can occur between mmap/munmap and journaling(ext3).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446086" id="446086">crash formatting a DVD under libata</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448115" id="448115">Guest crash when host has >= 64G RAM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448588" id="448588">RFE: improve gettimeofday performance on hypervisors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448929" id="448929">[RHEL5 U1] Kernel NFS Connectathon Test#12, 12.1 Failing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449175" id="449175">E1000 driver enables TSOv6 for hardware that doesn't support it</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449346" id="449346">SMP 32bit RHEL5u1 and RHEL5u2 HVM domain might stop booting when start udev service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450862" id="450862">scsi_add_host() returns success even if the work_q was not created</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451063" id="451063">backport RUSAGE_THREAD support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451849" id="451849">ptrace(PTRACE_CONT, sig) kills app even if sig is blocked</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452120" id="452120">lazy umount causes pwd to fail silently (kernel)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452534" id="452534">[RFE] Enable raw devices on s390x</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454942" id="454942">RHEL5.2: ext3 panic in dx_probe</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454981" id="454981">CPUID driver does not support cpuid.4 and cpuid.0xb instruments</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455232" id="455232">RHEL5-U2 Installation hangs on p-series--7029, 2078</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455678" id="455678">DM-multipath marks the surviving path as failed on failbacks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456437" id="456437">[RHEL5.2-Z][kernel-xen] powernow identifies the wrong number of processors.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456698" id="456698">Module snd-sb16.ko fails to build in a custom kernel.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459397" id="459397">Cannot create more than 1024 nfsd threads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459449" id="459449">[Qlogic 5.4] qla4xxx: Remove Dead/Unused code from driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459943" id="459943">FEAT: kernel: nf_nat: backport NAT port randomisation [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460133" id="460133">NFS problem#3 of IT 106473 - 32-bit jiffy wrap around - NFS inode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460218" id="460218">GFS2: Hang when shrink_slab calls gfs2_delete_inode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460693" id="460693">Xen domU, RAID1, LVM, iscsi target export with blockio bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461006" id="461006">SCSI Hotswap not working with sym53c8xx_2 card in NSN MCP18 system.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461288" id="461288">[EMC 5.4 feat] Require kernel support to issue Control I/O to CKD dasd on EMC Symmetrix arrays</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461469" id="461469">device-mapper changes to support readonly device maps</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462248" id="462248">Debug Kernel - NMI Watchdog detected LOCKUP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462352" id="462352">[RHEL-5.2] e1000e module doesn't implement SIOETHTOOL ETHTOOL_GPERMADDR</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462572" id="462572">RHEL 5.1 show error msg of "PCI: BIOS Bug: MCFG area at e0000000 is not E820-reserved" during boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462725" id="462725">[RHEL-5.2] replacing routes doesn't emit notifications via netlink</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462731" id="462731">invalid behaviour of NETKEY / XFRM deleting SPD</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462911" id="462911">5.3 beta kernel -115.el breaks the proprietary Nvidia driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463244" id="463244">[PATCH] Removing bond interfaces causes workqueue thread leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463249" id="463249">document netdev_budget</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463573" id="463573">Patches to improve timekeeping for RHEL kernels running under VMware.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464039" id="464039">Timeouts in wait_drive_not_busy with TEAC DV-W28ECW and similar</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464500" id="464500">RHEL5: memmap=X$Y option doesn't yield new BIOS map</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465143" id="465143">update CIFS for RHEL5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465456" id="465456">Kernel panic in auth_rpcgss:__gss_find_upcall</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465543" id="465543">kernel module is required to enable kernel markers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465781" id="465781">MD RAID1 error handler deadlock (raid1d / make_request)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466086" id="466086">IPoIB-CM connectivity problem with eHCA adapters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466701" id="466701">RFE: an error when mounting the same NFS mount with different SELinux contexts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467698" id="467698">xen: 32 bit guest on 64 bit host oops in xen_set_pud()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467782" id="467782">unstable time source</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468088" id="468088">[EMULEX 5.4 bug] scsi messages correlate with silent data corruption, but no i/o errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468092" id="468092">number of lockd socket connections is capped at 80</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469130" id="469130">Xen live migration may fail due to fragmented memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469437" id="469437">ansi cprng needs to allow for user-provided initial counter values</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469707" id="469707">specfile changes to allow just building the debug kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469848" id="469848">[RHEL5.2] nfs_getattr() hangs during heavy write workloads</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470035" id="470035">xm dmesg printk spam -- Domain attempted WRMSR 00000000000000e8 from 00000016:3d0e9470 to 00000000:00000000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470059" id="470059">IPv6 netfilter: output routing rules based on fwmark don't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470074" id="470074">overlapping nfs locks don't work in gfs/dlm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470111" id="470111">FIPS certification requires exporting DSA_verify function</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470139" id="470139">stack usage optimization in link_path_walk() [rhel-5.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470202" id="470202">Kernel Panic at  pci_scan_bus_parented+0xa/0x1f  with "acpi=off" or "acpi=ht" options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470459" id="470459">The system stall or panic can occur when /proc/&lt;pid>/oom_score is read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470929" id="470929">rng header needs to be in kernel-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471254" id="471254">lockd: fix reference count leaks in async locking case (impacts GFS2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471281" id="471281">crypto: ansi_cprng: get_prng_bytes returning some incorrect data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471565" id="471565">Creation of mirrored logical volume with VG extent-size of 1K fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471800" id="471800">Driver for dm9601 doesn't seem to work as advertised</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471893" id="471893">kernel's inotify subsystem not send notification on inode link count change</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471900" id="471900">[QLogic 5.4 feat] qla2xxx,qla8xxx - Support production FCoE hardware.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472386" id="472386">fips crypto: self-test needed for rfc4309(ccm(aes))</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472426" id="472426">missing compat sys_ustat corrupts userspace when sys_ustat called from 32-bit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472523" id="472523">AMD: Panic if cpu_khz is incorrect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472547" id="472547">[RHEL5.4 FEAT] Update ixgbe to version 2.0.8-k2 and support the 82599 (Niantic) device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472558" id="472558">oops in mirror_map (dm-raid1.c)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473504" id="473504">kernel panic in tcp_tso_segment() (iptables/netfilter)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473947" id="473947">asm-generic/ioctl.h can generate link error undefined __invalid_size_argument_for_IOC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474091" id="474091">[Intel 5.4 FEAT] TSC keeps running in C3+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474240" id="474240">[RHEL5.1] Support of Broadcom HT1100 chipset - add new PCI ID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474301" id="474301">[AMD 5.4 FEAT] Withdraw IGN_SERR_INTERNAL for SB800 SATA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474334" id="474334">r8169 reports incredible number of RX dropped packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474394" id="474394">crypto: des3_ede single-key doesn't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474590" id="474590">lockd: return NLM_LCK_DENIED_GRACE_PERIOD after long periods</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474646" id="474646">[LTC 5.4 FEAT] Kernel NSS support - kernel part [200790]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474664" id="474664">[LTC 5.4 FEAT] System z support for processor degradation [200975]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474688" id="474688">[LTC 5.4 FEAT] Automatic IPL after dump (kernel) [201169]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474699" id="474699">After successful connection to a WPA AP, iwlagn loses its ability to speak WEP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474797" id="474797">[RHEL 5] gen_estimator deadlock fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474881" id="474881">[Intel 5.4 FEAT] Update the Intel igb driver to match upstream changes &amp; include Kawela PF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474891" id="474891">PCI Domain support for HP xw9400 and xw9300</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474913" id="474913">[LTC 5.4 FEAT] Thread scalability issues with TPC-C [201300]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475145" id="475145">audit: increase the maximum length of the key field</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475147" id="475147">fix assorted audit_filter_task() panics on ctx == NULL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475149" id="475149">audit: fix kstrdup() error check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475150" id="475150">kernel/audit.c control character detection is off-by-one</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475278" id="475278">missing audit records for descriptors created by pipe(2) and socketpair(2)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475312" id="475312">GFS2: mount attempt hangs if no more journals available</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475330" id="475330">Misc kernel audit fixups</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475334" id="475334">[LTC 5.4 FEAT] FCP - Performance Data collection  (kernel) [201590]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475374" id="475374">Make clock source functions consistent between x86_64 &amp; i386 arches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475530" id="475530">[LTC 5.4 FEAT] Extra kernel parameter via VMPARM [201726]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475536" id="475536">[LTC 5.4 FEAT] OpenIPMI driver update [201263]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475551" id="475551">[LTC 5.4 FEAT] TTY terminal server over IUCV (kernel) [201734]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475563" id="475563">[LTC 5.4 FEAT] Shutdown actions interface (kernel) [201747]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475567" id="475567">[Broadcom 5.4 FEAT] Update bnx2 to 1.8.2b+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475570" id="475570">[LTC 5.4 FEAT] Provide service levels of HW &amp; Hypervisor in Linux [201753]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475572" id="475572">[LTC 5.4 FEAT] HiperSockets Layer3 support for IPv6 [201751]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475620" id="475620">[LTC 5.4 FEAT] Update spufs for Cell in the kernel of RHEL5.4 to the upstream version [201774]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475621" id="475621">[LTC 5.4 FEAT] Enable SOL (serial over lan) usage for Cell systems with RHEL5 [201454]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475625" id="475625">[Intel 5.4 bug] ixgbe does not work reliably with 16 or more cores</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475658" id="475658">[LTC 5.4 FEAT] Enable Power Button on Cell Blades [201777]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475696" id="475696">[LTC 5.4 FEAT] EEH infrastructure change for MSI-X interrupt support [201779]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475717" id="475717">[LTC 5.4 FEAT] Enhance the ipr driver to support MSI-X interrupt [201780]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475790" id="475790">Compilation failure with /usr/include/linux/futex.h header</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475814" id="475814">race in aio_complete() leads to process hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475820" id="475820">[LTC 5.4 FEAT] Linux to add Call Home data [201167]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475986" id="475986">Question for LUKS device passhprase unreadable when using Xen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476206" id="476206">ahci: jmb361 has only one port</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476224" id="476224">convert NFS to new write_begin/write_end interfaces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476301" id="476301">[Chelsio FEAT] Update support for Terminator3 adapters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476626" id="476626">GFS2: [RFE] fiemap support for GFS2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476659" id="476659">softlockups due to infinite loops in posix_locks_deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476707" id="476707">GFS2: [RFE] Merge upstream uevent patches into RHEL 5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476897" id="476897">kernel panics when attempting to rmmod the bnx2 module while it is in use.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477005" id="477005">lockdep warnings on RHEL5.3 xen guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477012" id="477012">network hangs with xen_vnif in FV RHEL5 guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477206" id="477206">[LTC 5.4 FEAT] Xen support for 192 CPUs [201257]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478638" id="478638">kernel-2.6.18-92.1.22.el5 misses bug fix which has to be backported.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478643" id="478643">multipath test causes memory leak and eventual system deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479200" id="479200">[Broadcom 5.4 feat] Please add pcie_set_readrq() to the rhel5_drivers_pci_pcie_ga kernel symbol whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479288" id="479288">[QLOGIC 5.4 feat] Add qlge 10Gb ethernet driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479401" id="479401">GFS2: Parsing of remount arguments incorrect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479412" id="479412">PATH and EXECVE audit records contain bogus newlines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479740" id="479740">[RHEL 5.1] SUN Ultra 40 forcedeth: Network freezes reproducibly (stress) evebe600</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479754" id="479754">RH5.3 x64 RC2 reboots while installing a virtual machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479765" id="479765">Leap second message can hang the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479927" id="479927">Needs to check GSO packet length against MSS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480142" id="480142">/proc/acpi/dsdt: No such device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480204" id="480204">[QLogic 5.4 bug] qla2xxx - updates and fixes from upstream, part 1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480663" id="480663">data corruption and general brokenness with ramdisks (rd)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480696" id="480696">RDMA latencytest and perftest fail with QLogic IB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480733" id="480733">2 volume rebuilding problem - second volume rebuild doesn't succeed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480939" id="480939">RHEL-5: Deadlock in Xen netfront driver.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480951" id="480951">Improve udp port randomization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481031" id="481031">crypto: panic handling ccm vectors with null associated data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481076" id="481076">kernel BUG at net/ipv4/netfilter/ip_nat_core.c:308</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481175" id="481175">need to backport several ansi_cprng patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481199" id="481199">waitpid() reports stopped process more than once</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481226" id="481226">Bitmap Merging Patch for RHEL 5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481283" id="481283">[RHEL5.3] Original ether's status is keeping PROMISC MULTICAST mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481682" id="481682">linux-2.6-misc-utrace-update.patch contains incorrect optimization</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481691" id="481691">[QLogic 5.4 bug] qla2xx - Word-endian problem programming flash on PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481715" id="481715">BCM5704 NIC results in CPU 100%SI , sluggish system performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482737" id="482737">Add explicit ALUA support to kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482796" id="482796">eHEA: mutex_unlock missing in eHEA error path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482990" id="482990">RHEL 5.3 GA kernel panics when RF Kill is on in 5100/5300 AGN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483171" id="483171">Panic at boot if SATA disk is present</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483285" id="483285">fix oops when using skb_seq_read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483541" id="483541">gfs2 blocked after recovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483588" id="483588">[RFE ] Connlimit kernel module support [rhel-5.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483594" id="483594">FEAT: RHEL 5.4 - update ALSA HDA audio driver from upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483617" id="483617">reproducible panic in debugfs_remove when unmounting gfs2 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483790" id="483790">[IPV6] Fix the return value of get destination options with NULL data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483793" id="483793">[ipv6] Fix the return value of Set Hop-by-Hop options header with NULL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483814" id="483814">kernel BUG at kernel/ptrace.c:1068</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484105" id="484105">[IPV6] Return correct result for sticky options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484158" id="484158">FEAT: feature request. disable iostat collection in gendisk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484227" id="484227">[Intel 5.4 FEAT] virtualization feature VTd: hypervisor changes (Xen)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484304" id="484304">[RHEL-5.3] ARP packets aren't received by backup slaves breaking arp_validate=3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484403" id="484403">Add kernel version to oops and panic output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484590" id="484590">Running Openswan ipsec vpn server with rhel-5.3 kernel-2.6.18-128.el5 causes crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484796" id="484796">tulip driver MTU problems when using dot1q vlans</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484836" id="484836">DASDFMT not operating like CPFMTXA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484943" id="484943">[Stratus 5.4 bug] PCI hot unplug can leak MSI descriptors causing fallback to legacy interrupts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484971" id="484971">[IPv6] Update setsockopt(IPV6_MULTICAST_IF) to support RFC 3493, try2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484977" id="484977">[IPV6]: Check length of optval provided by user in setsockopt()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485098" id="485098">NULL pointer deference in gfs2_getbuf</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485181" id="485181">Dock/Undock+ CDROM support for X61 and other laptops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485182" id="485182">Data  cards like Huawei EC121 does not work with RHEL5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485226" id="485226">GFS2 unaligned access in gfs2_bitfit</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485315" id="485315">ext4 kernelspace rebase for RHEL5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485381" id="485381">backport critical netxen driver fixes from upstream kernel to RHEL5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485718" id="485718">Add mmu-notifiers support to RHEL5 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486030" id="486030">[iwl3945] Status LED doesn't light up (Lenovo T61)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486168" id="486168">GFS2: Quota mount option inconsistent with common quota/noquota options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486185" id="486185">pci_setup_bridge() clears the Prefetchable Memory Base and Limit Upper 32 Bits registers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486204" id="486204">[ipv6 RAW] Disallow IPPROTO_IPV6-level IPV6_CHECKSUM socket option on ICMPv6 sockets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486215" id="486215">[IPV6] Check outgoing interface even if source address is unspecified</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486756" id="486756">nfs server rejecting large writes when sec=krb5i/p is specified</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487213" id="487213">[Intel 5.4 bug] ixgbe driver double counts RX byte count</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487293" id="487293">Missing DELL MD3000i storage into scsi_dh_rdac kernel module device list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487406" id="487406">[ipv6] Check the hop limit setting in ancillary data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487672" id="487672">slab corruption with dlm and clvmd on ppc64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487691" id="487691">[RHEL5.3]: modprobe xen-vnif in a KVM guest causes a crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487929" id="487929">CVE-2009-0745 kernel: ext4: ext4_group_add() missing initialisation issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487935" id="487935">CVE-2009-0746 kernel: ext4: make_indexed_dir() missing validation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487942" id="487942">CVE-2009-0747 kernel: ext4: ext4_isize() denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487945" id="487945">CVE-2009-0748 kernel: ext4: ext4_fill_super() missing validation issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488367" id="488367">[NET] Fix functions put_cmsg()/put_cmsg_compat() which may cause usr application memory overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488471" id="488471">Problem with drive status leds after update to 2.6.18-128.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488820" id="488820">update efifb</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488964" id="488964">RHEL 5.4: hpilo - backport of bugfixes and updates from upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489096" id="489096">install include/trace/*.h headers in kernel-devel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489274" id="489274">[RHEL5.3 Xen]: Cannot attach > 16 PV disks using PV-on-HVM drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489285" id="489285">Backport lookupcache= mount option for nfs shares</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489389" id="489389">[QLOGIC 5.4 bug] qla4xxx: Extended Sense Data Errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490078" id="490078">"automount" daemon gets blocked uninterruptibly while trying to acquire "i_sem" of monitored directory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490162" id="490162">ethttool -S on r8169 version 2.2LK hangs when interface is down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490181" id="490181">NFS: an f_mode/f_flags confusion in fs/nfs/write.c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490567" id="490567">[RHEL5.3 Xen]: Annoying messages on i686 boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490938" id="490938">[x86_64]: copy_user_c can zero more data than needed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491266" id="491266">kernel should be built with -fwrapv [rhel-5.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491685" id="491685">vmalloc_user() panics 2.6.18-128.1.1.el5 if a kmem cache grows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491775" id="491775">building of kernel-devel on i386 doesn't include asm-x86_64/stacktrace.h</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492010" id="492010">powernow-k8: export module parameters to /sys/modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492488" id="492488">Driver core: make bus_find_device_by_name() more robust</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492866" id="492866">Xen guest kernel  advertises absolute mouse pointer feature which it is incapable of setting up correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492911" id="492911">tar off gfs2 broken - truncated symbolic links</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492943" id="492943">GFS2: gfs2_quotad in uninterruptible sleep while idle</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492972" id="492972">[RHEL5.2] [IPV6] TUNNEL6: Fix incoming packet length check for inter-protocol tunnel.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493045" id="493045">memory leak when reading from files mounted with nfs mount option 'noac'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493088" id="493088">Kprobes bugfixes backport from 2.6.29</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493144" id="493144">panic in SELinux code with shrinkable NFS mounts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493152" id="493152">[Intel 5.4 FEAT] virtualization feature SR/IOV: kernel changes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493448" id="493448">The SCSI tape driver (st) does not support writing with larger buffers when using aic7xxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493451" id="493451">Upgrade to update 3 causes SATA resets.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494114" id="494114">2.6.18-128.1.6.el5xen panic!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494288" id="494288">CPU P-state limits (via acpi _ppc) ignored by OS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494658" id="494658">With Red Hat errata 128.1.6 installed system hangs with SATA drives installed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494876" id="494876">[RHEL5.4]: Explicitly zero CR[1] in getvcpucontext</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494879" id="494879">[RHEL5.4]: Fix interaction between dom0 and NTP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494885" id="494885">GFS2: gfs2_grow changes to rindex read in wrong by the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495092" id="495092">[QLogic 5.4 bug] qla2xxx - updates and fixes from upstream, part 2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495094" id="495094">[QLogic 5.4 bug] qla2xxx - updates and fixes from upstream, part 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495125" id="495125">ptrace: wrong value for bp register at syscall entry tracing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495230" id="495230">kernel dm: OOps in mempool_free when device removed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495318" id="495318">Bonding driver updelay parameter actual behavior doesn't match documented behavior</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495442" id="495442">vmscan: bail out of direct reclaim after swap_cluster_max pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495612" id="495612">Export guest UUID through SMBIOS to show in guest dmidecode by default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495863" id="495863">kernel: tun: Add packet accounting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495866" id="495866">show_partition() oops when race with rescan_partitions()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496100" id="496100">Random crashing in dm snapshots because of a race condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496101" id="496101">kernel BUG with dm multipath and a partial read request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496102" id="496102">Backport patches for snapshot store damage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496126" id="496126">[QLogic 5.4 bug] qla2xxx - updates and fixes from upstream, part 4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496338" id="496338">sata_mv: Fix chip type for Highpoint RocketRaid 1740/1742</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496766" id="496766">autofs4 - obvious mistake in mounted check in autofs4_mount_busy()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496869" id="496869">[Intel 5.4 FEAT] virtualization feature VTd: kernel changes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496873" id="496873">[Intel 5.4 FEAT] virtualization feature enhanced VTd: hypervisor changes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496903" id="496903">Setacl not working over NFS.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497411" id="497411">kernel BUG at drivers/scsi/libiscsi.c:301!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497414" id="497414">add 'success' value to sched_wakeup and sched_wakeup_new tracepoints</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497478" id="497478">[QLOGIC 5.4 bug] qla4xxx: Driver Fault Recovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498281" id="498281">dont use DID_TRANSPORT_DISRUPTED when transitioning rport or iscsi states</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498527" id="498527">ehca performance impact during creation of queue pairs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498719" id="498719">[patch] mac80211: nullfunc and hidden SSID fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499013" id="499013">Deadlock between libvirt and xentop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499171" id="499171">kernel: ecryptfs_parse_options: eCryptfs: unrecognized option 'ecryptfs_unlink_sigs'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499202" id="499202">New compilation warning in ext4 rebase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499289" id="499289">RHEL5.3.z LTP nanosleep02 Test Case Failure on Fujitsu Machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499347" id="499347">Add Generic Receive Offload support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499406" id="499406">device-mapper: dm-raid45 target doesn't create parity as expected by dmraid (isw)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499541" id="499541">kernel: proc: avoid information leaks to non-privileged processes [rhel-5.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499840" id="499840">nfsv4recoverydir proc file unreadable</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499870" id="499870">Wacom driver with Intuos tablet does not report button press after a proximity leave/re-enter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499999" id="499999">ath5k module freezes when interface is brought down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500311" id="500311">Kernel panic when loading cpufreq_governor</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500368" id="500368">NETDEV_BONDING_FAILOVER is defined twice in the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500387" id="500387">device-mapper: dm-raid45 target regression causing oops on mapping table reload</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500446" id="500446">[RHEL5.4] igb: debug kernel reveals incorrect call used to free multiqueue netdev</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500568" id="500568">kernel-xen should *not* include pci-stub  driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500693" id="500693">LTP ftest04 and ftest08 Failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500729" id="500729">Deadlock when a uevent is blocked waiting for the queued I/O.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500745" id="500745">Need symbols added to KABI whitelist for cmirror-kmod</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500839" id="500839">renaming file on a share w/o write permissions causes oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500857" id="500857">[RHEL5 U4] Systems seems to hang on reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500892" id="500892">Kernel - testing NMI watchdog ... CPU#0: NMI appears to be stuck (0)!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501082" id="501082">RHEL5.4 ext4: backport corruption fixes from .30</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501178" id="501178">RHEL5: NMI lockups seen after enabling cpuspeed on -147.el5 &amp; -148.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501308" id="501308">REGRESSION: iSCSI Target's Redirect login causes errors in connection</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501321" id="501321">Removal of directory doesn't produce audit record if rule is recursive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501374" id="501374">disable MSI on VIA VT3364 chipsets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501468" id="501468">RHEL5.4 virtio: "Device does not have a release() function, it is broken and must be fixed" warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501474" id="501474">[RHEL5.4 Xen]: Xenbus warnings in a FV guest on shutdown</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501475" id="501475">[RHEL5.4 Xen]: "Weight assignment" messages printed to the serial console</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502944" id="502944">READ CAPACITY failed on 10TB LUN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503080" id="503080">need to fix sky2 stats</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503191" id="503191">[RHEL5.4 Xen]: Tun patch causing connectathon to fail</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503215" id="503215">igb: dropping rx packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503248" id="503248">[Emulex 5.4 bug] Update lpfc to version 8.2.0.44</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503309" id="503309">qemu-kvm: page allocation failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503737" id="503737">[RHEL5.4 Xen]: Trying to boot a FV -PAE kernel crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503818" id="503818">Xen dom0 fake e820 prevents IGB driver from creating VF devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503826" id="503826">PCI device fails to allocate resource</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503827" id="503827">sata_sx4: ata_cmd_set_features time out resulting in disabled device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503905" id="503905">kernel: TPM: get_event_name stack corruption [rhel-5.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503960" id="503960">System freezes when removing ipr driver after injecting EEH errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504086" id="504086">GFS2: s_umount locking bug with gfs2meta filesystem type</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504121" id="504121">RHEL 5.3 long installation time and low hard disk performance in VX800 platform</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504181" id="504181">[Broadcom 5.4 bug] Include fixes/cleanups for bnx2i</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504676" id="504676">gfs2: extending direct IO writes expose stale data (corruption)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504906" id="504906">iw_cxgb3 OFED driver update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504955" id="504955">RHEL5.4: cxgb3 update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505171" id="505171">gfs2: filesystem consistency error with statfs_slow = 1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505445" id="505445">[Emulex 5.4 bug] Update lpfc to version 8.2.0.45 (bug fixes only)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505491" id="505491">32-bit Dom0 Cannot Boot in RHEL5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505541" id="505541">BUG: soft lockup - CPU#0 stuck for 10s! [NetworkManager:5182]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505548" id="505548">1921270 - gfs2 filesystem won't free up space when files are deleted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505601" id="505601">ext4 preallocation corruption with truncate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505653" id="505653">[RHEL5.4] ixgbe fixups for version 2.0.8-k2 specifically the 82599</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506138" id="506138">need to backport upstream commit 4ea7e38696c7e798c47ebbecadfd392f23f814f9 from net-next</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506140" id="506140">GFS2: Filesystem deadlock when running SPECsfs on BIGI test bed.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506151" id="506151">RHEL5.4: cxgb3i (open-iscsi) update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506511" id="506511">performance regression running Iozone with different I/O options on RHEL54 kernels</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506792" id="506792">[Emulex 5.4 bug] Update lpfc to version 8.2.0.46 (bug fixes only)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506841" id="506841">RHEL5.4 -154 e1000e using MSI-X hangs system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506845" id="506845">Kernel panic unplugging a rt73usb dongle</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506981" id="506981">[QLogic 5.4 bug] qla4xxx: Testing updates, 4 fixes.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507017" id="507017">mmap_min_addr can trigger on non MAP_FIXED mmap operations</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507246" id="507246">[QLogic 5.4 bug] qla2xxx - updates and fixes from upstream, part 5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507398" id="507398">[QLogic 5.4 bug] qla2xxx - updates 24xx / 25xx firmware to 4.04.09</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507520" id="507520">xen kernel, modprobe -r popup call trace and error msg</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507620" id="507620">[QLogic 5.4 bug] qla2xxx - properly handle event notification in FCoE environment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/507932" id="507932">[RHEL 5.4] sky2: /proc/net/dev statistics are broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508297" id="508297">RTNL: assertion failed due to bonding notify.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508409" id="508409">RHEL 5.4 cxgb3i (open-iscsi) connection error through VLAN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508806" id="508806">GFS2 panics while shrinking the glock cache.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508839" id="508839">[Emulex 5.4 bug] be2net: traffic stops when using INTx interrupts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508870" id="508870">No network traffic when igb network interface receives arp traffic during negotiation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508871" id="508871">[Emulex 5.4 bug] Unload of bonding driver causes be2net driver to deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/508876" id="508876">umount.gfs2 hangs eating CPU</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509010" id="509010">[Emulex 5.4 bug] Update lpfc to version 8.2.0.48 (bug fixes only)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509207" id="509207">VT-d BUG() during normal traffic in ixgbe device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509526" id="509526">(RHEL 5.4 Alpha/Beta x86 ) no audio output on IbexPeak chipset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509647" id="509647">[QLogic 5.4 bug] qlge - testing fixes part 3.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/509818" id="509818">cciss: spinlock deadlock causes NMI on HP systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510008" id="510008">[Emulex 5.4 bug] Lower throughput seen on be2net with MSIx interrupt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510268" id="510268">qla2xxx - NPIV broken for PPC, endian fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510665" id="510665">megaraid sas driver in rhel5.4-beta fails to scan for SAS tape drive (HP Ultrium 4-SCSI)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510805" id="510805">PCI FLR support needed for secure device assignment to KVM guests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511096" id="511096">bnx2i and libiscsi: make sure cnic dev is registered and fix libiscsi eh_abort locking</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511141" id="511141">qla2xxx - Provide fundamental reset capability for EEH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511181" id="511181">kernel: build with -fno-delete-null-pointer-checks [rhel-5.4]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512086" id="512086">RHEL5.4: Add SATA GEN3 related messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512266" id="512266">[Emulex 5.4 bug] Update lpfc driver to 8.2.0.48.2p to fix multiple panics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512387" id="512387">max_phys_segments violation with dm-linear + md raid1 + cciss</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513067" id="513067">ahci: add device IDs for Ibex Peak SATA AHCI controllers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513070" id="513070">cciss disk devices do not have storage capability in HAL</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513802" id="513802">[Broadcom 5.4 bug] cnic ISCSI_KEVENT_IF_DOWN message handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514073" id="514073">RHEL 5.4 cxgb3i (open-iscsi) hits skb_over_panic() on write</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515392" id="515392">CVE-2009-2847 kernel: information leak in sigaltstack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515423" id="515423">CVE-2009-2848 kernel: execve: must clear current->clear_child_tid</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243004" comment="kernel-headers is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243002" comment="kernel is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243024" comment="kernel-doc is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243020" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243006" comment="kernel-devel is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243010" comment="kernel-debug is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243016" comment="kernel-kdump is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243012" comment="kernel-xen-devel is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243014" comment="kernel-debug-devel is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243022" comment="kernel-PAE is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243018" comment="kernel-kdump-devel is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091243008" comment="kernel-xen is earlier than 0:2.6.18-164.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091278" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1278: lftp security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1278-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1278.html" />
          <reference source="CVE" ref_id="CVE-2007-2348" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2348.html" />
    
    <description>LFTP is a sophisticated file transfer program for the FTP and HTTP
protocols. Like bash, it has job control and uses the readline library for
input. It has bookmarks, built-in mirroring, and can transfer several files
in parallel. It is designed with reliability in mind.

It was discovered that lftp did not properly escape shell metacharacters
when generating shell scripts using the "mirror --script" command. A
mirroring script generated to download files from a malicious FTP server
could allow an attacker controlling the FTP server to run an arbitrary
command as the user running lftp. (CVE-2007-2348)

This update also fixes the following bugs:

* when using the "mirror" or "get" commands with the "-c" option, lftp did
not check for some specific conditions that could result in the program
becoming unresponsive, hanging and the command not completing. For example,
when waiting for a directory listing, if lftp received a "226" message,
denoting an empty directory, it previously ignored the message and kept
waiting. With this update, these conditions are properly checked for and
lftp no longer hangs when "-c" is used with "mirror" or "get". (BZ#422881)

* when using the "put", "mput" or "reput" commands over a Secure FTP (SFTP)
connection, specifying the "-c" option sometimes resulted in corrupted
files of incorrect size. With this update, using these commands over SFTP
with the "-c" option works as expected, and transferred files are no
longer corrupted in the transfer process. (BZ#434294)

* previously, LFTP linked to the OpenSSL library. OpenSSL's license is,
however, incompatible with LFTP's GNU GPL license and LFTP does not include
an exception allowing OpenSSL linking. With this update, LFTP links to the
GnuTLS (GNU Transport Layer Security) library, which is released under the
GNU LGPL license. Like OpenSSL, GnuTLS implements the SSL and TLS
protocols, so functionality has not changed. (BZ#458777)

* running "help mirror" from within lftp only presented a sub-set of the
available options compared to the full list presented in the man page. With
this update, running "help mirror" in lftp presents the same list of mirror
options as is available in the Commands section of the lftp man page.
(BZ#461922)

* LFTP imports gnu-lib from upstream. Subsequent to gnu-lib switching from
GNU GPLv2 to GNU GPLv3, the LFTP license was internally inconsistent, with
LFTP licensed as GNU GPLv2 but portions of the package apparently licensed
as GNU GPLv3 because of changes made by the gnu-lib import. With this
update, LFTP itself switches to GNU GPLv3, resolving the inconsistency.
(BZ#468858)

* when the "ls" command was used within lftp to present a directory listing
on a remote system connected to via HTTP, file names containing spaces were
presented incorrectly. This update corrects this behavior. (BZ#504591)

* the default alias "edit" did not define a default editor. If EDITOR was
not set in advance by the system, lftp attempted to execute
"~/.lftp/edit.tmp.$$" (which failed because the file is not set to
executable). The edit alias also did not support tab-completion of file
names and incorrectly interpreted file names containing spaces. The updated
package defines a default editor (vi) in the absence of a system-defined
EDITOR. The edit alias now also supports tab-completion and handles file
names containing spaces correctly for both downloading and uploading.
(BZ#504594)

Note: This update upgrades LFTP from version 3.7.3 to upstream version
3.7.11, which incorporates a number of further bug fixes to those noted
above. For details regarding these fixes, refer to the
"/usr/share/doc/lftp-3.7.11/NEWS" file after installing this update.
(BZ#308721)

All LFTP users are advised to upgrade to this updated package, which
resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2348.html">CVE-2007-2348</cve>
                <bugzilla href="http://bugzilla.redhat.com/236238" id="236238">CVE-2007-2348 lftp mirror --script does not escape names and targets of symbolic links</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239334" id="239334">lftp affected by problems described in CVE-2007-2348</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/308721" id="308721">bump lftp to current version 3.7.11</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/422881" id="422881">Using lftp with -c options causes hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434294" id="434294">lftp corrupts data when using (m)put's -c option on sftp transport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461922" id="461922">[RHEL 5] lftp 'help mirror' does not display all options defined in manpage.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091278002" comment="lftp is earlier than 0:3.7.11-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091278003" comment="lftp is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091287" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1287: openssh security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1287-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1287.html" />
          <reference source="CVE" ref_id="CVE-2008-5161" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5161.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A flaw was found in the SSH protocol. An attacker able to perform a
man-in-the-middle attack may be able to obtain a portion of plain text from
an arbitrary ciphertext block when a CBC mode cipher was used to encrypt
SSH communication. This update helps mitigate this attack: OpenSSH clients
and servers now prefer CTR mode ciphers to CBC mode, and the OpenSSH server
now reads SSH packets up to their full possible length when corruption is
detected, rather than reporting errors early, reducing the possibility of
successful plain text recovery. (CVE-2008-5161)

This update also fixes the following bug:

* the ssh client hung when trying to close a session in which a background
process still held tty file descriptors open. With this update, this
so-called "hang on exit" error no longer occurs and the ssh client closes
the session immediately. (BZ#454812)

In addition, this update adds the following enhancements:

* the SFTP server can now chroot users to various directories, including
a user's home directory, after log in. A new configuration option --
ChrootDirectory -- has been added to "/etc/ssh/sshd_config" for setting
this up (the default is not to chroot users). Details regarding configuring
this new option are in the sshd_config(5) manual page. (BZ#440240)

* the executables which are part of the OpenSSH FIPS module which is being
validated will check their integrity and report their FIPS mode status to
the system log or to the terminal. (BZ#467268, BZ#492363)

All OpenSSH users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues and add these
enhancements. After installing this update, the OpenSSH server daemon
(sshd) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5161.html">CVE-2008-5161</cve>
                <bugzilla href="http://bugzilla.redhat.com/440240" id="440240">request to add chroot sftp capabilty into openssh-server</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472068" id="472068">CVE-2008-5161 OpenSSH: Plaintext Recovery Attack against CBC ciphers</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091287002" comment="openssh is earlier than 0:4.3p2-36.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287003" comment="openssh is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091287004" comment="openssh-clients is earlier than 0:4.3p2-36.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287005" comment="openssh-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091287008" comment="openssh-server is earlier than 0:4.3p2-36.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287009" comment="openssh-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091287006" comment="openssh-askpass is earlier than 0:4.3p2-36.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287007" comment="openssh-askpass is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091289" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1289: mysql security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1289-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1289.html" />
          <reference source="CVE" ref_id="CVE-2008-2079" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2079.html" />
          <reference source="CVE" ref_id="CVE-2008-3963" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-3963.html" />
          <reference source="CVE" ref_id="CVE-2008-4456" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4456.html" />
          <reference source="CVE" ref_id="CVE-2009-2446" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2446.html" />
    
    <description>MySQL is a multi-user, multi-threaded SQL database server. It consists of
the MySQL server daemon (mysqld) and many client programs and libraries.

MySQL did not correctly check directories used as arguments for the DATA
DIRECTORY and INDEX DIRECTORY directives. Using this flaw, an authenticated
attacker could elevate their access privileges to tables created by other
database users. Note: This attack does not work on existing tables. An
attacker can only elevate their access to another user's tables as the
tables are created. As well, the names of these created tables need to be
predicted correctly for this attack to succeed. (CVE-2008-2079)

A flaw was found in the way MySQL handles an empty bit-string literal. A
remote, authenticated attacker could crash the MySQL server daemon (mysqld)
if they used an empty bit-string literal in an SQL statement. This issue
only caused a temporary denial of service, as the MySQL daemon was
automatically restarted after the crash. (CVE-2008-3963)

An insufficient HTML entities quoting flaw was found in the mysql command
line client's HTML output mode. If an attacker was able to inject arbitrary
HTML tags into data stored in a MySQL database, which was later retrieved
using the mysql command line client and its HTML output mode, they could
perform a cross-site scripting (XSS) attack against victims viewing the
HTML output in a web browser. (CVE-2008-4456)

Multiple format string flaws were found in the way the MySQL server logs
user commands when creating and deleting databases. A remote, authenticated
attacker with permissions to CREATE and DROP databases could use these
flaws to formulate a specifically-crafted SQL command that would cause a
temporary denial of service (open connections to mysqld are terminated).
(CVE-2009-2446)

Note: To exploit the CVE-2009-2446 flaws, the general query log (the mysqld
"--log" command line option or the "log" option in "/etc/my.cnf") must be
enabled. This logging is not enabled by default.

This update also fixes multiple bugs. Details regarding these bugs can be
found in the Red Hat Enterprise Linux 5.4 Technical Notes. You can find a
link to the Technical Notes in the References section of this errata.

Note: These updated packages upgrade MySQL to version 5.0.77 to incorporate
numerous upstream bug fixes. Details of these changes are found in the
following MySQL Release Notes:
http://dev.mysql.com/doc/refman/5.0/en/news-5-0-77.html

All MySQL users are advised to upgrade to these updated packages, which
resolve these issues. After installing this update, the MySQL server
daemon (mysqld) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2079.html">CVE-2008-2079</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-3963.html">CVE-2008-3963</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4456.html">CVE-2008-4456</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2446.html">CVE-2009-2446</cve>
                <bugzilla href="http://bugzilla.redhat.com/435494" id="435494">Timeout error starting MySQL when using non-default socket file value (fix provided)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445222" id="445222">CVE-2008-2079 mysql: privilege escalation via DATA/INDEX DIRECTORY directives</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448534" id="448534">upgrade to RHEL5.2 - breaks mysql replication between MasterDB and Slave</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450178" id="450178">Somewhat dubious code in mysqld init.d script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452824" id="452824">mysql-server crash permanently</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453156" id="453156">DATE function used in WHERE clause - broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455619" id="455619">tmpdir variable not honored for internally created temporary tables</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457218" id="457218">'Explicit or implicit commit' error/server crash with concurrent transactions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462071" id="462071">CVE-2008-3963 MySQL: Using an empty binary value leads to server crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462534" id="462534">SQL Config files should not be read more than once</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466518" id="466518">CVE-2008-4456 mysql: mysql command line client XSS flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470036" id="470036">Got query result when using ORDER BY ASC, but    empty result when using DESC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476896" id="476896">CVE-2008-3963 MySQL: Using an empty binary value leads to server crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511020" id="511020">CVE-2009-2446 MySQL: Format string vulnerability by manipulation with database instances (crash)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091289010" comment="mysql-test is earlier than 0:5.0.77-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091289011" comment="mysql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091289002" comment="mysql is earlier than 0:5.0.77-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091289003" comment="mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091289006" comment="mysql-server is earlier than 0:5.0.77-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091289007" comment="mysql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091289004" comment="mysql-bench is earlier than 0:5.0.77-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091289005" comment="mysql-bench is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091289008" comment="mysql-devel is earlier than 0:5.0.77-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091289009" comment="mysql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091307" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1307: ecryptfs-utils security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1307-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1307.html" />
          <reference source="CVE" ref_id="CVE-2008-5188" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5188.html" />
    
    <description>eCryptfs is a stacked, cryptographic file system. It is transparent to the
underlying file system and provides per-file granularity.

eCryptfs is released as a Technology Preview for Red Hat Enterprise Linux
5.4. These updated ecryptfs-utils packages have been upgraded to upstream
version 75, which provides a number of bug fixes and enhancements over the
previous version. In addition, these packages provide a graphical program
to help configure and use eCryptfs. To start this program, run the command:

	ecryptfs-mount-helper-gui

Important: the syntax of certain eCryptfs mount options has changed. Users
who were previously using the initial Technology Preview release of
ecryptfs-utils are advised to refer to the ecryptfs(7) man page, and to
update any affected mount scripts and /etc/fstab entries for eCryptfs file
systems.

A disclosure flaw was found in the way the "ecryptfs-setup-private" script
passed passphrases to the "ecryptfs-wrap-passphrase" and
"ecryptfs-add-passphrase" commands as command line arguments. A local user
could obtain the passphrases of other users who were running the script
from the process listing. (CVE-2008-5188)

These updated packages provide various enhancements, including a mount
helper and supporting libraries to perform key management and mounting
functions.

Notable enhancements include:

* a new package, ecryptfs-utils-gui, has been added to this update. This
package depends on the pygtk2 and pygtk2-libglade packages and provides the
eCryptfs Mount Helper GUI program. To install the GUI, first install
ecryptfs-utils and then issue the following command:

	yum install ecryptfs-utils-gui

(BZ#500997)

* the "ecryptfs-rewrite-file" utility is now more intelligent when dealing
with non-existent files and with filtering special files such as the "."
directory. In addition, the progress output from "ecryptfs-rewrite-file"
has been improved and is now more explicit about the success status of each
target. (BZ#500813)

* descriptions of the "verbose" flag and the "verbosity=[x]" option, where
[x] is either 0 or 1, were missing from a number of eCryptfs manual pages,
and have been added. Refer to the eCryptfs man pages for important
information regarding using the verbose and/or verbosity options.
(BZ#470444)

These updated packages also fix the following bugs:

* mounting a directory using the eCryptfs mount helper with an RSA key that
was too small did not allow the eCryptfs mount helper to encrypt the entire
key. When this situation occurred, the mount helper did not display an
error message alerting the user to the fact that the key size was too
small, possibly leading to corrupted files. The eCryptfs mount helper now
refuses RSA keys which are to small to encrypt the eCryptfs key.
(BZ#499175)

* when standard input was redirected from /dev/null or was unavailable,
attempting to mount a directory with the eCryptfs mount helper caused it to
become unresponsive and eventually crash, or an "invalid value" error
message, depending on if the "--verbosity=[value]" option was provided as
an argument, and, if so, its value. With these updated packages, attempting
to mount a directory using "mount.ecryptfs" under the same conditions
results in either the mount helper attempting to use default values (if
"verbosity=0" is supplied), or an "invalid value" error message (instead of
the mount helper hanging) if standard input is redirected and
"--verbosity=1" is supplied, or that option is omitted entirely.
(BZ#499367)

* attempting to use the eCryptfs mount helper with an OpenSSL key when the
keyring did not contain enough space for the key resulted in an unhelpful
error message. The user is now alerted when this situation occurs.
(BZ#501460)

* the eCryptfs mount helper no longer fails upon receiving an incorrect or
empty answer to "yes/no" questions. (BZ#466210)

Users are advised to upgrade to these updated ecryptfs-utils packages,
which resolve these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5188.html">CVE-2008-5188</cve>
                <bugzilla href="http://bugzilla.redhat.com/460496" id="460496">ecryptfs complains about a missing module, fails and then loads it</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472524" id="472524">CVE-2008-5188 ecryptfs-utils: potential provided password disclosure in the process table</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475969" id="475969">difference between the name of the binary and the name in its usage message</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482834" id="482834">RHEL5: update ecryptfs-utils to latest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499128" id="499128">`man ecryptfs' is wrong on what to write to openssl_passwd_file=XXX</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499367" id="499367">mount.ecrytfs hangs when used with wrong/missing stdin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500352" id="500352">mount helper asks different set questions when the mount options are OK and when are not</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500361" id="500361">[ecryptfs-add-passphrase] adding key, which is in keyring already, results in error msg</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500566" id="500566">When kernel does not support filename encryption `ecryptfs-add-passphrase --fnek' should exit with exit code != 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500623" id="500623">Access-Your-Private-Data.desktop file should have an icon associated</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500804" id="500804">Typo in ecryptfs-rewrite-file(1)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500810" id="500810">ecryptfs-insert-wrapped-passphrase-into-keyring fails to add passphrase to keyring if the passphrase is in the keyring already</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500813" id="500813">ecryptfs-rewrite-file should be more wise when dealing with non-existing/bogus files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500817" id="500817">ecryptfs-dot-private is not expected to be executed, remove the "x" permission</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500820" id="500820">ecryptfs-setup-swap: vol_id: command not found</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500824" id="500824">Possible missing runtime dependencies for `ecryptfs-setup-swap'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500829" id="500829">`ecryptfs-setup-swap' tries to restart service ``cryptdisks'' which is not present in RHEL/Fedora</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500850" id="500850">[RFE] ecryptfs-manager should ask for password confirmation when creating openssl key</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500997" id="500997">ecryptfs-utils-gui must require pygtk2-libglade</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501275" id="501275">Select key bytes: item "default" is bogus</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501460" id="501460">Error msg from ecryptfs-utils does not reflect reality when adding key to "full" keyring</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091307004" comment="ecryptfs-utils-devel is earlier than 0:75-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091307005" comment="ecryptfs-utils-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091307002" comment="ecryptfs-utils is earlier than 0:75-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091307003" comment="ecryptfs-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091307006" comment="ecryptfs-utils-gui is earlier than 0:75-5.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091307007" comment="ecryptfs-utils-gui is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091321" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1321: nfs-utils security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1321-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1321.html" />
          <reference source="CVE" ref_id="CVE-2008-4552" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4552.html" />
    
    <description>The nfs-utils package provides a daemon for the kernel NFS server and
related tools.

It was discovered that nfs-utils did not use tcp_wrappers correctly.
Certain hosts access rules defined in "/etc/hosts.allow" and
"/etc/hosts.deny" may not have been honored, possibly allowing remote
attackers to bypass intended access restrictions. (CVE-2008-4552)

This updated package also fixes the following bugs:

* the "LOCKD_TCPPORT" and "LOCKD_UDPPORT" options in "/etc/sysconfig/nfs"
were not honored: the lockd daemon continued to use random ports. With this
update, these options are honored. (BZ#434795)

* it was not possible to mount NFS file systems from a system that has
the "/etc/" directory mounted on a read-only file system (this could occur
on systems with an NFS-mounted root file system). With this update, it is
possible to mount NFS file systems from a system that has "/etc/" mounted
on a read-only file system. (BZ#450646)

* arguments specified by "STATDARG=" in "/etc/sysconfig/nfs" were removed
by the nfslock init script, meaning the arguments specified were never
passed to rpc.statd. With this update, the nfslock init script no longer
removes these arguments. (BZ#459591)

* when mounting an NFS file system from a host not specified in the NFS
server's "/etc/exports" file, a misleading "unknown host" error was logged
on the server (the hostname lookup did not fail). With this update, a
clearer error message is provided for these situations. (BZ#463578)

* the nhfsstone benchmark utility did not work with NFS version 3 and 4.
This update adds support to nhfsstone for NFS version 3 and 4. The new
nhfsstone "-2", "-3", and "-4" options are used to select an NFS version
(similar to nfsstat(8)). (BZ#465933)

* the exportfs(8) manual page contained a spelling mistake, "djando", in
the EXAMPLES section. (BZ#474848)

* in some situations the NFS server incorrectly refused mounts to hosts
that had a host alias in a NIS netgroup. (BZ#478952)

* in some situations the NFS client used its cache, rather than using
the latest version of a file or directory from a given export. This update
adds a new mount option, "lookupcache=", which allows the NFS client to
control how it caches files and directories. Note: The Red Hat Enterprise
Linux 5.4 kernel update (the fourth regular update) must be installed in
order to use the "lookupcache=" option. Also, "lookupcache=" is currently
only available for NFS version 3. Support for NFS version 4 may be
introduced in future Red Hat Enterprise Linux 5 updates. Refer to Red Hat
Bugzilla #511312 for further information. (BZ#489335)

Users of nfs-utils should upgrade to this updated package, which contains
backported patches to correct these issues. After installing this update,
the nfs service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4552.html">CVE-2008-4552</cve>
                <bugzilla href="http://bugzilla.redhat.com/434795" id="434795">lockd not using settings in sysconfig/nfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450646" id="450646">/sbin/mount.nfs fails with read-only /etc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458676" id="458676">CVE-2008-4552 nfs-utils: incorrect use of tcp_wrappers, causing hostname-based rules to be ignored</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459591" id="459591">rpc.statd options not correctly parsed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463578" id="463578">confusing 'mount request from unknown host' messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465933" id="465933">nhfsstone does not support NFSv3 and v4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474848" id="474848">typo in exportfs manpage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489335" id="489335">Add support for lookupcache= option in nfs-utils.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091321002" comment="nfs-utils is earlier than 1:1.0.9-42.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091321003" comment="nfs-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091335" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1335: openssl security, bug fix, and enhancement update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1335-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1335.html" />
          <reference source="CVE" ref_id="CVE-2009-0590" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0590.html" />
          <reference source="CVE" ref_id="CVE-2009-1377" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1377.html" />
          <reference source="CVE" ref_id="CVE-2009-1378" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1378.html" />
          <reference source="CVE" ref_id="CVE-2009-1379" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1379.html" />
          <reference source="CVE" ref_id="CVE-2009-1386" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1386.html" />
          <reference source="CVE" ref_id="CVE-2009-1387" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1387.html" />
    
    <description>OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols, as well as a full-strength
general purpose cryptography library. Datagram TLS (DTLS) is a protocol
based on TLS that is capable of securing datagram transport (for example,
UDP).

Multiple denial of service flaws were discovered in OpenSSL's DTLS
implementation. A remote attacker could use these flaws to cause a DTLS
server to use excessive amounts of memory, or crash on an invalid memory
access or NULL pointer dereference. (CVE-2009-1377, CVE-2009-1378,
CVE-2009-1379, CVE-2009-1386, CVE-2009-1387)

Note: These flaws only affect applications that use DTLS. Red Hat does not
ship any DTLS client or server applications in Red Hat Enterprise Linux.

An input validation flaw was found in the handling of the BMPString and
UniversalString ASN1 string types in OpenSSL's ASN1_STRING_print_ex()
function. An attacker could use this flaw to create a specially-crafted
X.509 certificate that could cause applications using the affected function
to crash when printing certificate contents. (CVE-2009-0590)

Note: The affected function is rarely used. No application shipped with Red
Hat Enterprise Linux calls this function, for example.

These updated packages also fix the following bugs:

* "openssl smime -verify -in" verifies the signature of the input file and
the "-verify" switch expects a signed or encrypted input file. Previously,
running openssl on an S/MIME file that was not encrypted or signed caused
openssl to segfault. With this update, the input file is now checked for a
signature or encryption. Consequently, openssl now returns an error and
quits when attempting to verify an unencrypted or unsigned S/MIME file.
(BZ#472440)

* when generating RSA keys, pairwise tests were called even in non-FIPS
mode. This prevented small keys from being generated. With this update,
generating keys in non-FIPS mode no longer calls the pairwise tests and
keys as small as 32-bits can be generated in this mode. Note: In FIPS mode,
pairwise tests are still called and keys generated in this mode must still
be 1024-bits or larger. (BZ#479817)

As well, these updated packages add the following enhancements:

* both the libcrypto and libssl shared libraries, which are part of the
OpenSSL FIPS module, are now checked for integrity on initialization of
FIPS mode. (BZ#475798)

* an issuing Certificate Authority (CA) allows multiple certificate
templates to inherit the CA's Common Name (CN). Because this CN is used as
a unique identifier, each template had to have its own Certificate
Revocation List (CRL). With this update, multiple CRLs with the same
subject name can now be stored in a X509_STORE structure, with their
signature field being used to distinguish between them. (BZ#457134)

* the fipscheck library is no longer needed for rebuilding the openssl
source RPM. (BZ#475798)

OpenSSL users should upgrade to these updated packages, which resolve these
issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0590.html">CVE-2009-0590</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1377.html">CVE-2009-1377</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1378.html">CVE-2009-1378</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1379.html">CVE-2009-1379</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1386.html">CVE-2009-1386</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1387.html">CVE-2009-1387</cve>
                <bugzilla href="http://bugzilla.redhat.com/479817" id="479817">Do not call pairwise tests in non-FIPS mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492304" id="492304">CVE-2009-0590 openssl: ASN1 printing crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501253" id="501253">CVE-2009-1377 OpenSSL: DTLS epoch record buffer memory DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501254" id="501254">CVE-2009-1378 OpenSSL: DTLS fragment handling memory DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501572" id="501572">CVE-2009-1379 OpenSSL: DTLS pointer use-after-free flaw (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503685" id="503685">CVE-2009-1386 openssl: DTLS NULL deref crash on early ChangeCipherSpec request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503688" id="503688">CVE-2009-1387 openssl: DTLS out-of-sequence message handling NULL deref DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091335002" comment="openssl is earlier than 0:0.9.8e-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004005" comment="openssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091335004" comment="openssl-perl is earlier than 0:0.9.8e-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004007" comment="openssl-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091335006" comment="openssl-devel is earlier than 0:0.9.8e-12.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004009" comment="openssl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091337" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1337: gfs2-utils security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1337-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1337.html" />
          <reference source="CVE" ref_id="CVE-2008-6552" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6552.html" />
    
    <description>The gfs2-utils package provides the user-space tools necessary to mount,
create, maintain, and test GFS2 file systems.

Multiple insecure temporary file use flaws were discovered in GFS2 user
level utilities. A local attacker could use these flaws to overwrite an
arbitrary file writable by a victim running those utilities (typically
root) with the output of the utilities via a symbolic link attack.
(CVE-2008-6552)

This update also fixes the following bugs:

* gfs2_fsck now properly detects and repairs problems with sequence numbers
on GFS2 file systems.

* GFS2 user utilities now use the file system UUID.

* gfs2_grow now properly updates the file system size during operation.

* gfs2_fsck now returns the proper exit codes.

* gfs2_convert now properly frees blocks when removing free blocks up to
height 2.

* the gfs2_fsck manual page has been renamed to fsck.gfs2 to match current
standards.

* the 'gfs2_tool df' command now provides human-readable output.

* mounting GFS2 file systems with the noatime or noquota option now works
properly.

* new capabilities have been added to the gfs2_edit tool to help in testing
and debugging GFS and GFS2 issues.

* the 'gfs2_tool df' command no longer segfaults on file systems with a
block size other than 4k.

* the gfs2_grow manual page no longer references the '-r' option, which has
been removed.

* the 'gfs2_tool unfreeze' command no longer hangs during use.

* gfs2_convert no longer corrupts file systems when converting from GFS to
GFS2.

* gfs2_fsck no longer segfaults when encountering a block which is listed
as both a data and stuffed directory inode.

* gfs2_fsck can now fix file systems even if the journal is already locked
for use.

* a GFS2 file system's metadata is now properly copied with 'gfs2_edit
savemeta' and 'gfs2_edit restoremeta'.

* the gfs2_edit savemeta function now properly saves blocks of type 2.

* 'gfs2_convert -vy' now works properly on the PowerPC architecture.

* when mounting a GFS2 file system as '/', mount_gfs2 no longer fails after
being unable to find the file system in '/proc/mounts'.

* gfs2_fsck no longer segfaults when fixing 'EA leaf block type' problems.

All gfs2-utils users should upgrade to this updated package, which resolves
these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6552.html">CVE-2008-6552</cve>
                <bugzilla href="http://bugzilla.redhat.com/242701" id="242701">Add Filesystem UUID to GFS2 utils.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469773" id="469773">GFS2: gfs2_grow doesn't grow file system properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474705" id="474705">GFS2: make gfs2_fsck conform to fsck(8) exit codes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474707" id="474707">GFS2: gfs2_convert not freeing blocks when removing file with height >=2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477072" id="477072">gfs2_fsck man page should be fsck.gfs2 man page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481762" id="481762">No longer able to mount GFS volume with noatime,noquota options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483799" id="483799">GFS2: gfs2_edit fixes for 5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485761" id="485761">GFS2: gfs2_tool df segfault on non-4K block size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486034" id="486034">gfs2_grow man page references removed -r option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487608" id="487608">GFS2: gfs2_tool unfreeze hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498646" id="498646">gfs2_fsck does not fix filesystem when 'journal is already locked for use'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501732" id="501732">mount failure after gfs2_edit restoremeta of GFS file system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502056" id="502056">GFS2: gfs2_edit savemeta needs to save freemeta blocks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/506629" id="506629">GFS2: gfs2_convert, parameter not understood on ppc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510758" id="510758">fsck.gfs2 segfaults while fixing 'EA leaf block type' problem.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519436" id="519436">CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091337002" comment="gfs2-utils is earlier than 0:0.1.62-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091337003" comment="gfs2-utils is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091339" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1339: rgmanager security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1339-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1339.html" />
          <reference source="CVE" ref_id="CVE-2008-6552" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6552.html" />
    
    <description>The rgmanager package contains the Red Hat Resource Group Manager, which
provides high availability for critical server applications in the event of
system downtime.

Multiple insecure temporary file use flaws were discovered in rgmanager and
various resource scripts run by rgmanager. A local attacker could use these
flaws to overwrite an arbitrary file writable by the rgmanager process
(i.e. user root) with the output of rgmanager or a resource agent via a
symbolic link attack. (CVE-2008-6552)

This update also fixes the following bugs:

* clulog now accepts '-' as the first character in messages.

* if expire_time is 0, max_restarts is no longer ignored.

* the SAP resource agents included in the rgmanager package shipped with
Red Hat Enterprise Linux 5.3 were outdated. This update includes the most
recent SAP resource agents and, consequently, improves SAP failover
support.

* empty PID files no longer cause resource start failures.

* recovery policy of type 'restart' now works properly when using a
resource based on ra-skelet.sh.

* samba.sh has been updated to kill the PID listed in the proper PID file.

* handling of the '-F' option has been improved to fix issues causing
rgmanager to crash if no members of a restricted failover domain were
online.

* the number of simultaneous status checks can now be limited to prevent
load spikes.

* forking and cloning during status checks has been optimized to reduce
load spikes.

* rg_test no longer hangs when run with large cluster configuration files.

* when rgmanager is used with a restricted failover domain it will no
longer occasionally segfault when some nodes are offline during a failover
event.

* virtual machine guests no longer restart after a cluster.conf update.

* nfsclient.sh no longer leaves temporary files after running.

* extra checks from the Oracle agents have been removed.

* vm.sh now uses libvirt.

* users can now define an explicit service processing order when
central_processing is enabled.

* virtual machine guests can no longer start on 2 nodes at the same time.

* in some cases a successfully migrated virtual machine guest could restart
when the cluster.conf file was updated.

* incorrect reporting of a service being started when it was not started
has been addressed.

As well, this update adds the following enhancements:

* a startup_wait option has been added to the MySQL resource agent.

* services can now be prioritized.

* rgmanager now checks to see if it has been killed by the OOM killer and
if so, reboots the node.

Users of rgmanager are advised to upgrade to this updated package, which
resolves these issues and adds these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6552.html">CVE-2008-6552</cve>
                <bugzilla href="http://bugzilla.redhat.com/250718" id="250718">fs.sh inefficient scripting leads to load peaks and disk saturation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/412911" id="412911">Convert all XM management calls to either lib virt or virsh</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449394" id="449394">Recovery policy of type restart doesn't work with a service using a resource based on ra-skelet.sh</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468691" id="468691">Virtual Services guest can start on 2 nodes at same time</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470917" id="470917">The oracledb.sh script checks in strange intervals(10s, 5m, 4.5m)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471066" id="471066">rgmanager oracledb.sh resource agent does not properly check for all db startup failures.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471226" id="471226">oracledb.sh script kills ALL oracle instances when failing over</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471431" id="471431">second ocf_log message doesn't make it to /var/log/messages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474444" id="474444">Zero-length pid files cause resource start failures</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475826" id="475826">Update support for SAP resource agents (rgmanager)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481058" id="481058">MySQL Service Startup Timeout after Crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482858" id="482858">Cluster Event Script needs Updates to include Group Exclusive</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483093" id="483093">rgmanager: samba.sh tries to kill the wrong pid file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486349" id="486349">nfsclient.sh leaves temporary files /tmp/nfsclient-status-cache-$$</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486717" id="486717">clusvcadm -e &lt;service> -F handling bugs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488714" id="488714">Enabling (according to failover domain rules) a frozen service results in a unusable failed+frozen service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489785" id="489785">/usr/share/cluster/apache.sh does not handle a valid /etc/httpd/conf/httpd.conf configuration correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490449" id="490449">domU's restart after cluster.conf update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490455" id="490455">rg_test hangs when running against cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492828" id="492828">RFE: priorities for services/virtual machines</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494977" id="494977">segfault in check_rdomain_crash() during failover</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505340" id="505340">VM migration and subsequent cluster.conf update can cause the VM restart</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514044" id="514044">vm.sh does will fail resource if "no state" is detected</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519436" id="519436">CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_cluster</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091339002" comment="rgmanager is earlier than 0:2.0.52-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091339003" comment="rgmanager is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091341" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1341: cman security, bug fix, and enhancement update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1341-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1341.html" />
          <reference source="CVE" ref_id="CVE-2008-4579" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-4579.html" />
          <reference source="CVE" ref_id="CVE-2008-6552" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-6552.html" />
    
    <description>The Cluster Manager (cman) utility provides services for managing a Linux
cluster.

Multiple insecure temporary file use flaws were found in fence_apc_snmp and
ccs_tool. A local attacker could use these flaws to overwrite an arbitrary
file writable by a victim running those utilities (typically root) with
the output of the utilities via a symbolic link attack. (CVE-2008-4579,
CVE-2008-6552)

Bug fixes:

* a buffer could overflow if cluster.conf had more than 52 entries per
block inside the &lt;cman> block. The limit is now 1024.

* the output of the group_tool dump subcommands were NULL padded.

* using device="" instead of label="" no longer causes qdiskd to
incorrectly exit.

* the IPMI fencing agent has been modified to time out after 10 seconds. It
is also now possible to specify a different timeout value with the '-t'
option.

* the IPMI fencing agent now allows punctuation in passwords.

* quickly starting and stopping the cman service no longer causes the
cluster membership to become inconsistent across the cluster.

* an issue with lock syncing caused 'receive_own from' errors to be logged
to '/var/log/messages'.

* an issue which caused gfs_controld to segfault when mounting hundreds of
file systems has been fixed.

* the LPAR fencing agent now properly reports status when an LPAR is in
Open Firmware mode.

* the LPAR fencing agent now works properly with systems using the
Integrated Virtualization Manager (IVM).

* the APC SNMP fencing agent now properly recognizes outletStatusOn and
outletStatusOff return codes from the SNMP agent.

* the WTI fencing agent can now connect to fencing devices with no
password.

* the rps-10 fencing agent now properly performs a reboot when run with no
options.

* the IPMI fencing agent now supports different cipher types with the '-C'
option.

* qdisk now properly scans devices and partitions.

* cman now checks to see if a new node has state to prevent killing the
first node during cluster setup.

* 'service qdiskd start' now works properly.

* the McData fence agent now works properly with the McData Sphereon 4500
Fabric Switch.

* the Egenera fence agent can now specify an SSH login name.

* the APC fence agent now works with non-admin accounts when using the
3.5.x firmware.

* fence_xvmd now tries two methods to reboot a virtual machine.

* connections to OpenAIS are now allowed from unprivileged CPG clients with
the user and group of 'ais'.

* groupd no longer allows the default fence domain to be '0', which
previously caused rgmanager to hang. Now, rgmanager no longer hangs.

* the RSA fence agent now supports SSH enabled RSA II devices.

* the DRAC fence agent now works with the Integrated Dell Remote Access
Controller (iDRAC) on Dell PowerEdge M600 blade servers.

* fixed a memory leak in cman.

* qdisk now displays a warning if more than one label is found with the
same name.

* the DRAC5 fencing agent now shows proper usage instructions for the '-D'
option.

* cman no longer uses the wrong node name when getnameinfo() fails.

* the SCSI fence agent now verifies that sg_persist is installed.

* the DRAC5 fencing agent now properly handles modulename.

* QDisk now logs warning messages if it appears its I/O to shared storage
is hung.

* fence_apc no longer fails with a pexpect exception.

* removing a node from the cluster using 'cman_tool leave remove' now
properly reduces the expected_votes and quorum.

* a semaphore leak in cman has been fixed.

* 'cman_tool nodes -F name' no longer segfaults when a node is out of
membership.

Enhancements:

* support for: ePowerSwitch 8+ and LPAR/HMC v3 devices, Cisco MDS 9124 and
MDS 9134 SAN switches, the virsh fencing agent, and broadcast communication
with cman.

* fence_scsi limitations added to fence_scsi man page.

Users of cman are advised to upgrade to these updated packages, which
resolve these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-4579.html">CVE-2008-4579</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-6552.html">CVE-2008-6552</cve>
                <bugzilla href="http://bugzilla.redhat.com/276541" id="276541">fence_impilan blocks alternative fencing agents when connectivity to IPMI fails.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/322291" id="322291">rps-10 fence agent does not perform default reboot action</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447497" id="447497">RFE: support for IPMI v2.0 ciphersuites in fence_ipmilan</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447964" id="447964">fence_ipmilan does not handle punctuation in password</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467386" id="467386">CVE-2008-4579 cman/fence: insecure temporary file usage in the apc fence agents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468966" id="468966">Possible buffer overflow in cman config loader can lead to memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472460" id="472460">cman_tool nodes -F name segfaults when a node is out of membership</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472786" id="472786">cluster view inconsistent after "service cman stop; service cman start"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473961" id="473961">clvmd memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474163" id="474163">gfs_controld: receive_own from N messages with plock_ownership enabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480178" id="480178">fence_xvmd Fails to Reboot VM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480401" id="480401">gfs_controld segfault during multiple mount attempt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480836" id="480836">[RFE] Add support for Cisco 9124 and 9134 SAN switches as fence devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481566" id="481566">[PATCH] /sbin/fence_lpar - properly report status on systems in Open Firmware</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481664" id="481664">fence_wti is unable to connect to (password-less) fencing device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484095" id="484095">fence_apc_snmp: invalid status outletStatusOff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484956" id="484956">qdiskd does not prune partitions mapped to dm-mpio devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485026" id="485026">Cman kills first node in initial cluster setup</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485199" id="485199">'service qdiskd restart' doesn't work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485469" id="485469">Normal users cannot run CPG clients if openais is started by cman.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485700" id="485700">fence_lpar doesn't work with hmc version 3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487436" id="487436">Qdisk should choose first disk if multiple disks containing same label exist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487501" id="487501">Exceptions in fencing agents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488565" id="488565">cman uses local node name for lookup during start up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488958" id="488958">GFS: Allow fence_egenera to specify ssh login name</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491640" id="491640">APC Fence Agent does not work with non-admin account</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493165" id="493165">group_tool ls fence returns one for fence id ZERO</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493207" id="493207">groupd assigns zero group id</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493802" id="493802">[RFE] Providing support for ssh enabled RSA II fence devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496629" id="496629">[RFE] Include fence_virsh along with the present agents</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496724" id="496724">fence_drac5 uses module_name instead of modulename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/498329" id="498329">fence_drac5 help output shows incorrect usage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499767" id="499767">groupd segfaults on start</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500450" id="500450">qdiskd I/O hang reporting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500567" id="500567">Flag added to openais to report security errors causes cman not to build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501586" id="501586">fence agents (fence_apc, fence_wti) fails with pexpect exception</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502674" id="502674">fence_lpar can't log in to IVM systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/504705" id="504705">fence_lpar: lssyscfg command on HMC can take longer than SHELL_TIMEOUT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505258" id="505258">cman_tool leave remove does not reduce quorum</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505594" id="505594">semaphore leak during cluster startup/shutdown cycle</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512998" id="512998">Fence_scsi limitations man page fix needed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/514758" id="514758">[RHEL5][cman] fence_apc_snmp: local variable 'verbose_filename' referenced before assignment</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519436" id="519436">CVE-2008-6552 cman, gfs2-utils, rgmanager: multiple insecure temporary file use issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091341002" comment="cman is earlier than 0:2.0.115-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091341003" comment="cman is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091341004" comment="cman-devel is earlier than 0:2.0.115-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091341005" comment="cman-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091364" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1364: gdm security and bug fix update (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1364-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1364.html" />
          <reference source="CVE" ref_id="CVE-2009-2697" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2697.html" />
    
    <description>The GNOME Display Manager (GDM) is a configurable re-implementation of XDM,
the X Display Manager. GDM allows you to log in to your system with the X
Window System running, and supports running several different X sessions on
your local machine at the same time.

A flaw was found in the way the gdm package was built. The gdm package was
missing TCP wrappers support, which could result in an administrator
believing they had access restrictions enabled when they did not.
(CVE-2009-2697)

This update also fixes the following bugs:

* the GDM Reference Manual is now included with the gdm packages. The
gdm-docs package installs this document in HTML format in
"/usr/share/doc/". (BZ#196054)

* GDM appeared in English on systems using Telugu (te_IN). With this
update, GDM has been localized in te_IN. (BZ#226931)

* the Ctrl+Alt+Backspace sequence resets the X server when in runlevel 5.
In previous releases, however, repeated use of this sequence prevented GDM
from starting the X server as part of the reset process. This was because
GDM sometimes did not notice the X server shutdown properly and would
subsequently fail to complete the reset process. This update contains an
added check to explicitly notify GDM whenever the X server is terminated,
ensuring that resets are executed reliably. (BZ#441971)

* the "gdm" user is now part of the "audio" group by default. This enables
audio support at the login screen. (BZ#458331)

* the gui/modules/dwellmouselistener.c source code contained incorrect
XInput code that prevented tablet devices from working properly. This
update removes the errant code, ensuring that tablet devices work as
expected. (BZ#473262)

* a bug in the XOpenDevice() function prevented the X server from starting
whenever a device defined in "/etc/X11/xorg.conf" was not actually plugged
in. This update wraps XOpenDevice() in the gdk_error_trap_pop() and
gdk_error_trap_push() functions, which resolves this bug. This ensures that
the X server can start properly even when devices defined in
"/etc/X11/xorg.conf" are not plugged in. (BZ#474588)

All users should upgrade to these updated packages, which resolve these
issues. GDM must be restarted for this update to take effect. Rebooting
achieves this, but changing the runlevel from 5 to 3 and back to 5 also
restarts GDM.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-01" />
        <updated date="2009-09-02" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2697.html">CVE-2009-2697</cve>
                <bugzilla href="http://bugzilla.redhat.com/239818" id="239818">CVE-2009-2697 gdm not built with tcp_wrappers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441971" id="441971">[RHEL5] GDM sometimes doesn't come back after ctrl-alt-backspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458331" id="458331">Add supplementary audio group to the gdm user</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473262" id="473262">Mouse cursor not movable when using tablet instead of mouse</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474588" id="474588">gdmgreeter crashes if input device (ex wacom) is defined but not plugged</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091364004" comment="gdm-docs is earlier than 1:2.16.0-56.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091364005" comment="gdm-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091364002" comment="gdm is earlier than 1:2.16.0-56.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091364003" comment="gdm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091426" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1426: openoffice.org security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1426-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1426.html" />
          <reference source="CVE" ref_id="CVE-2009-0200" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0200.html" />
          <reference source="CVE" ref_id="CVE-2009-0201" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0201.html" />
    
    <description>OpenOffice.org is an office productivity suite that includes desktop
applications, such as a word processor, spreadsheet, presentation manager,
formula editor, and a drawing program.

An integer underflow flaw and a boundary error flaw, both possibly leading
to a heap-based buffer overflow, were found in the way OpenOffice.org
parses certain records in Microsoft Word documents. An attacker could
create a specially-crafted Microsoft Word document, which once opened by an
unsuspecting user, could cause OpenOffice.org to crash or, potentially,
execute arbitrary code with the permissions of the user running
OpenOffice.org. (CVE-2009-0200, CVE-2009-0201)

All users of OpenOffice.org are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. All
running instances of OpenOffice.org applications must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-04" />
        <updated date="2009-09-04" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0200.html">CVE-2009-0200</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0201.html">CVE-2009-0201</cve>
                <bugzilla href="http://bugzilla.redhat.com/500993" id="500993">CVE-2009-0200 OpenOffice.org Word document Integer Underflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502194" id="502194">CVE-2009-0201 OpenOffice.org Word document buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426144" comment="openoffice.org-langpack-xh_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426145" comment="openoffice.org-langpack-xh_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426002" comment="openoffice.org is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426003" comment="openoffice.org is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426082" comment="openoffice.org-langpack-tn_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426083" comment="openoffice.org-langpack-tn_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426044" comment="openoffice.org-langpack-af_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426045" comment="openoffice.org-langpack-af_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426136" comment="openoffice.org-langpack-nn_NO is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426137" comment="openoffice.org-langpack-nn_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426016" comment="openoffice.org-langpack-tr_TR is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426017" comment="openoffice.org-langpack-tr_TR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426062" comment="openoffice.org-langpack-te_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426063" comment="openoffice.org-langpack-te_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426006" comment="openoffice.org-calc is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426007" comment="openoffice.org-calc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426132" comment="openoffice.org-langpack-ss_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426133" comment="openoffice.org-langpack-ss_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426014" comment="openoffice.org-langpack-ml_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426015" comment="openoffice.org-langpack-ml_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426080" comment="openoffice.org-langpack-nl is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426081" comment="openoffice.org-langpack-nl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426116" comment="openoffice.org-testtools is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426117" comment="openoffice.org-testtools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426100" comment="openoffice.org-langpack-nb_NO is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426101" comment="openoffice.org-langpack-nb_NO is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426076" comment="openoffice.org-headless is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426077" comment="openoffice.org-headless is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426106" comment="openoffice.org-langpack-ta_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426107" comment="openoffice.org-langpack-ta_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426056" comment="openoffice.org-langpack-it is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426057" comment="openoffice.org-langpack-it is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426128" comment="openoffice.org-langpack-el_GR is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426129" comment="openoffice.org-langpack-el_GR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426102" comment="openoffice.org-base is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426103" comment="openoffice.org-base is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426142" comment="openoffice.org-langpack-es is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426143" comment="openoffice.org-langpack-es is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426008" comment="openoffice.org-langpack-da_DK is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426009" comment="openoffice.org-langpack-da_DK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426054" comment="openoffice.org-langpack-ca_ES is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426055" comment="openoffice.org-langpack-ca_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426032" comment="openoffice.org-langpack-cs_CZ is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426033" comment="openoffice.org-langpack-cs_CZ is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426038" comment="openoffice.org-draw is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426039" comment="openoffice.org-draw is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426118" comment="openoffice.org-langpack-ar is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426119" comment="openoffice.org-langpack-ar is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426098" comment="openoffice.org-langpack-sl_SI is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426099" comment="openoffice.org-langpack-sl_SI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426126" comment="openoffice.org-langpack-nr_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426127" comment="openoffice.org-langpack-nr_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426124" comment="openoffice.org-langpack-kn_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426125" comment="openoffice.org-langpack-kn_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426052" comment="openoffice.org-langpack-as_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426053" comment="openoffice.org-langpack-as_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426152" comment="openoffice.org-langpack-ts_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426153" comment="openoffice.org-langpack-ts_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426120" comment="openoffice.org-langpack-ja_JP is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426121" comment="openoffice.org-langpack-ja_JP is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426024" comment="openoffice.org-langpack-sk_SK is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426025" comment="openoffice.org-langpack-sk_SK is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426130" comment="openoffice.org-langpack-pt_PT is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426131" comment="openoffice.org-langpack-pt_PT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426154" comment="openoffice.org-langpack-cy_GB is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426155" comment="openoffice.org-langpack-cy_GB is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426140" comment="openoffice.org-langpack-zh_TW is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426141" comment="openoffice.org-langpack-zh_TW is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426046" comment="openoffice.org-langpack-st_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426047" comment="openoffice.org-langpack-st_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426084" comment="openoffice.org-langpack-ru is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426085" comment="openoffice.org-langpack-ru is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426078" comment="openoffice.org-xsltfilter is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426079" comment="openoffice.org-xsltfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426150" comment="openoffice.org-langpack-pa_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426151" comment="openoffice.org-langpack-pa_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426134" comment="openoffice.org-langpack-fi_FI is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426135" comment="openoffice.org-langpack-fi_FI is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426020" comment="openoffice.org-langpack-he_IL is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426021" comment="openoffice.org-langpack-he_IL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426108" comment="openoffice.org-langpack-ms_MY is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426109" comment="openoffice.org-langpack-ms_MY is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426050" comment="openoffice.org-langpack-bn is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426051" comment="openoffice.org-langpack-bn is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426028" comment="openoffice.org-graphicfilter is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426029" comment="openoffice.org-graphicfilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426066" comment="openoffice.org-pyuno is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426067" comment="openoffice.org-pyuno is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426092" comment="openoffice.org-writer is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426093" comment="openoffice.org-writer is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426030" comment="openoffice.org-langpack-bg_BG is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426031" comment="openoffice.org-langpack-bg_BG is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426088" comment="openoffice.org-langpack-hr_HR is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426089" comment="openoffice.org-langpack-hr_HR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426114" comment="openoffice.org-langpack-pl_PL is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426115" comment="openoffice.org-langpack-pl_PL is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426022" comment="openoffice.org-sdk is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426023" comment="openoffice.org-sdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426090" comment="openoffice.org-langpack-hi_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426091" comment="openoffice.org-langpack-hi_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426058" comment="openoffice.org-langpack-fr is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426059" comment="openoffice.org-langpack-fr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426010" comment="openoffice.org-langpack-pt_BR is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426011" comment="openoffice.org-langpack-pt_BR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426138" comment="openoffice.org-langpack-gu_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426139" comment="openoffice.org-langpack-gu_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426018" comment="openoffice.org-langpack-zu_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426019" comment="openoffice.org-langpack-zu_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426036" comment="openoffice.org-math is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426037" comment="openoffice.org-math is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426026" comment="openoffice.org-langpack-ur is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426027" comment="openoffice.org-langpack-ur is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426068" comment="openoffice.org-core is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426069" comment="openoffice.org-core is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426004" comment="openoffice.org-impress is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426005" comment="openoffice.org-impress is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426040" comment="openoffice.org-langpack-mr_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426041" comment="openoffice.org-langpack-mr_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426042" comment="openoffice.org-langpack-gl_ES is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426043" comment="openoffice.org-langpack-gl_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426148" comment="openoffice.org-langpack-hu_HU is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426149" comment="openoffice.org-langpack-hu_HU is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426122" comment="openoffice.org-langpack-et_EE is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426123" comment="openoffice.org-langpack-et_EE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426048" comment="openoffice.org-langpack-ko_KR is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426049" comment="openoffice.org-langpack-ko_KR is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426104" comment="openoffice.org-langpack-nso_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426105" comment="openoffice.org-langpack-nso_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426064" comment="openoffice.org-langpack-sr_CS is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426065" comment="openoffice.org-langpack-sr_CS is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426034" comment="openoffice.org-sdk-doc is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426035" comment="openoffice.org-sdk-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426074" comment="openoffice.org-langpack-or_IN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426075" comment="openoffice.org-langpack-or_IN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426146" comment="openoffice.org-javafilter is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426147" comment="openoffice.org-javafilter is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426012" comment="openoffice.org-emailmerge is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426013" comment="openoffice.org-emailmerge is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426094" comment="openoffice.org-langpack-ve_ZA is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426095" comment="openoffice.org-langpack-ve_ZA is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426110" comment="openoffice.org-langpack-lt_LT is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426111" comment="openoffice.org-langpack-lt_LT is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426086" comment="openoffice.org-langpack-eu_ES is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426087" comment="openoffice.org-langpack-eu_ES is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426072" comment="openoffice.org-langpack-zh_CN is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426073" comment="openoffice.org-langpack-zh_CN is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426070" comment="openoffice.org-langpack-sv is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426071" comment="openoffice.org-langpack-sv is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426112" comment="openoffice.org-langpack-ga_IE is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426113" comment="openoffice.org-langpack-ga_IE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426060" comment="openoffice.org-langpack-de is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426061" comment="openoffice.org-langpack-de is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426096" comment="openoffice.org-langpack-th_TH is earlier than 1:2.3.0-6.11.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426097" comment="openoffice.org-langpack-th_TH is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426159" comment="openoffice.org-i18n is earlier than 0:1.1.2-44.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426160" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426157" comment="openoffice.org is earlier than 0:1.1.2-44.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426158" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426161" comment="openoffice.org-libs is earlier than 0:1.1.2-44.2.0.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426162" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426165" comment="openoffice.org-i18n is earlier than 0:1.1.5-10.6.0.7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426160" comment="openoffice.org-i18n is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426164" comment="openoffice.org is earlier than 0:1.1.5-10.6.0.7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426158" comment="openoffice.org is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426168" comment="openoffice.org-libs is earlier than 0:1.1.5-10.6.0.7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426162" comment="openoffice.org-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426166" comment="openoffice.org-kde is earlier than 0:1.1.5-10.6.0.7.EL4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426167" comment="openoffice.org-kde is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426257" comment="openoffice.org2-langpack-ar is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426258" comment="openoffice.org2-langpack-ar is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426253" comment="openoffice.org2-xsltfilter is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426254" comment="openoffice.org2-xsltfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426245" comment="openoffice.org2-pyuno is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426246" comment="openoffice.org2-pyuno is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426231" comment="openoffice.org2-core is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426232" comment="openoffice.org2-core is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426227" comment="openoffice.org2-langpack-ms_MY is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426228" comment="openoffice.org2-langpack-ms_MY is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426213" comment="openoffice.org2-langpack-af_ZA is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426214" comment="openoffice.org2-langpack-af_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426209" comment="openoffice.org2-langpack-ca_ES is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426210" comment="openoffice.org2-langpack-ca_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426179" comment="openoffice.org2-langpack-he_IL is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426180" comment="openoffice.org2-langpack-he_IL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426259" comment="openoffice.org2-calc is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426260" comment="openoffice.org2-calc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426243" comment="openoffice.org2-base is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426244" comment="openoffice.org2-base is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426225" comment="openoffice.org2-langpack-et_EE is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426226" comment="openoffice.org2-langpack-et_EE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426197" comment="openoffice.org2-langpack-ta_IN is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426198" comment="openoffice.org2-langpack-ta_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426187" comment="openoffice.org2-emailmerge is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426188" comment="openoffice.org2-emailmerge is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426267" comment="openoffice.org2-langpack-el_GR is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426268" comment="openoffice.org2-langpack-el_GR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426265" comment="openoffice.org2-langpack-nl is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426266" comment="openoffice.org2-langpack-nl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426205" comment="openoffice.org2-math is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426206" comment="openoffice.org2-math is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426263" comment="openoffice.org2-writer is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426264" comment="openoffice.org2-writer is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426261" comment="openoffice.org2-langpack-gl_ES is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426262" comment="openoffice.org2-langpack-gl_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426223" comment="openoffice.org2-langpack-cy_GB is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426224" comment="openoffice.org2-langpack-cy_GB is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426241" comment="openoffice.org2-langpack-it is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426242" comment="openoffice.org2-langpack-it is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426169" comment="openoffice.org2 is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426170" comment="openoffice.org2 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426279" comment="openoffice.org2-draw is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426280" comment="openoffice.org2-draw is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426271" comment="openoffice.org2-langpack-bg_BG is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426272" comment="openoffice.org2-langpack-bg_BG is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426251" comment="openoffice.org2-langpack-cs_CZ is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426252" comment="openoffice.org2-langpack-cs_CZ is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426249" comment="openoffice.org2-langpack-sk_SK is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426250" comment="openoffice.org2-langpack-sk_SK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426239" comment="openoffice.org2-langpack-pt_PT is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426240" comment="openoffice.org2-langpack-pt_PT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426217" comment="openoffice.org2-langpack-sr_CS is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426218" comment="openoffice.org2-langpack-sr_CS is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426203" comment="openoffice.org2-langpack-th_TH is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426204" comment="openoffice.org2-langpack-th_TH is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426193" comment="openoffice.org2-langpack-hu_HU is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426194" comment="openoffice.org2-langpack-hu_HU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426191" comment="openoffice.org2-langpack-fr is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426192" comment="openoffice.org2-langpack-fr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426189" comment="openoffice.org2-langpack-de is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426190" comment="openoffice.org2-langpack-de is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426183" comment="openoffice.org2-langpack-lt_LT is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426184" comment="openoffice.org2-langpack-lt_LT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426177" comment="openoffice.org2-langpack-bn is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426178" comment="openoffice.org2-langpack-bn is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426269" comment="openoffice.org2-langpack-zh_CN is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426270" comment="openoffice.org2-langpack-zh_CN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426235" comment="openoffice.org2-langpack-pt_BR is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426236" comment="openoffice.org2-langpack-pt_BR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426221" comment="openoffice.org2-javafilter is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426222" comment="openoffice.org2-javafilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426199" comment="openoffice.org2-langpack-sl_SI is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426200" comment="openoffice.org2-langpack-sl_SI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426175" comment="openoffice.org2-langpack-zu_ZA is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426176" comment="openoffice.org2-langpack-zu_ZA is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426283" comment="openoffice.org2-langpack-nb_NO is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426284" comment="openoffice.org2-langpack-nb_NO is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426277" comment="openoffice.org2-testtools is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426278" comment="openoffice.org2-testtools is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426273" comment="openoffice.org2-langpack-eu_ES is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426274" comment="openoffice.org2-langpack-eu_ES is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426247" comment="openoffice.org2-langpack-sv is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426248" comment="openoffice.org2-langpack-sv is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426219" comment="openoffice.org2-langpack-gu_IN is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426220" comment="openoffice.org2-langpack-gu_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426215" comment="openoffice.org2-langpack-ga_IE is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426216" comment="openoffice.org2-langpack-ga_IE is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426201" comment="openoffice.org2-langpack-es is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426202" comment="openoffice.org2-langpack-es is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426185" comment="openoffice.org2-langpack-ru is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426186" comment="openoffice.org2-langpack-ru is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426281" comment="openoffice.org2-langpack-pa_IN is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426282" comment="openoffice.org2-langpack-pa_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426275" comment="openoffice.org2-langpack-da_DK is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426276" comment="openoffice.org2-langpack-da_DK is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426233" comment="openoffice.org2-impress is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426234" comment="openoffice.org2-impress is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426173" comment="openoffice.org2-langpack-ko_KR is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426174" comment="openoffice.org2-langpack-ko_KR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426285" comment="openoffice.org2-langpack-pl_PL is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426286" comment="openoffice.org2-langpack-pl_PL is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426255" comment="openoffice.org2-langpack-ja_JP is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426256" comment="openoffice.org2-langpack-ja_JP is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426237" comment="openoffice.org2-langpack-hr_HR is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426238" comment="openoffice.org2-langpack-hr_HR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426229" comment="openoffice.org2-graphicfilter is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426230" comment="openoffice.org2-graphicfilter is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426211" comment="openoffice.org2-langpack-zh_TW is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426212" comment="openoffice.org2-langpack-zh_TW is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426207" comment="openoffice.org2-langpack-hi_IN is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426208" comment="openoffice.org2-langpack-hi_IN is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426181" comment="openoffice.org2-langpack-tr_TR is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426182" comment="openoffice.org2-langpack-tr_TR is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426171" comment="openoffice.org2-langpack-fi_FI is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426172" comment="openoffice.org2-langpack-fi_FI is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091426195" comment="openoffice.org2-langpack-nn_NO is earlier than 1:2.0.4-5.7.0.6.0.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091426196" comment="openoffice.org2-langpack-nn_NO is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091427" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1427: fetchmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1427.html" />
          <reference source="CVE" ref_id="CVE-2007-4565" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-4565.html" />
          <reference source="CVE" ref_id="CVE-2008-2711" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-2711.html" />
          <reference source="CVE" ref_id="CVE-2009-2666" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2666.html" />
    
    <description>Fetchmail is a remote mail retrieval and forwarding utility intended for
use over on-demand TCP/IP links, such as SLIP and PPP connections.

It was discovered that fetchmail is affected by the previously published
"null prefix attack", caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse fetchmail into accepting it by mistake. (CVE-2009-2666)

A flaw was found in the way fetchmail handles rejections from a remote SMTP
server when sending warning mail to the postmaster. If fetchmail sent a
warning mail to the postmaster of an SMTP server and that SMTP server
rejected it, fetchmail could crash. (CVE-2007-4565)

A flaw was found in fetchmail. When fetchmail is run in double verbose
mode ("-v -v"), it could crash upon receiving certain, malformed mail
messages with long headers. A remote attacker could use this flaw to cause
a denial of service if fetchmail was also running in daemon mode ("-d").
(CVE-2008-2711)

Note: when using SSL-enabled services, it is recommended that the fetchmail
"--sslcertck" option be used to enforce strict SSL certificate checking.

All fetchmail users should upgrade to this updated package, which contains
backported patches to correct these issues. If fetchmail is running in
daemon mode, it must be restarted for this update to take effect (use the
"fetchmail --quit" command to stop the fetchmail process).</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-08" />
        <updated date="2009-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-4565.html">CVE-2007-4565</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-2711.html">CVE-2008-2711</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2666.html">CVE-2009-2666</cve>
                <bugzilla href="http://bugzilla.redhat.com/260601" id="260601">CVE-2007-4565 Fetchmail NULL pointer dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451758" id="451758">CVE-2008-2711 fetchmail: Crash in large log messages in verbose mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515804" id="515804">CVE-2009-2666 fetchmail: SSL null terminator bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091427002" comment="fetchmail is earlier than 0:6.3.6-1.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091427003" comment="fetchmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091427005" comment="fetchmail is earlier than 0:6.2.0-3.el3.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091427006" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091427008" comment="fetchmail is earlier than 0:6.2.5-6.0.1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091427006" comment="fetchmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091428" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1428: xmlsec1 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1428-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1428.html" />
          <reference source="CVE" ref_id="CVE-2009-0217" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0217.html" />
    
    <description>The XML Security Library is a C library based on libxml2 and OpenSSL. It
implements the XML Signature Syntax and Processing and XML Encryption
Syntax and Processing standards. HMAC is used for message authentication
using cryptographic hash functions. The HMAC algorithm allows the hash
output to be truncated (as documented in RFC 2104).

A missing check for the recommended minimum length of the truncated form of
HMAC-based XML signatures was found in xmlsec1. An attacker could use this
flaw to create a specially-crafted XML file that forges an XML signature,
allowing the attacker to bypass authentication that is based on the XML
Signature specification. (CVE-2009-0217)

Users of xmlsec1 should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, applications that use the XML Security Library must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-08" />
        <updated date="2009-09-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0217.html">CVE-2009-0217</cve>
                <bugzilla href="http://bugzilla.redhat.com/511915" id="511915">CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428016" comment="xmlsec1-nss-devel is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428017" comment="xmlsec1-nss-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428004" comment="xmlsec1-openssl is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428005" comment="xmlsec1-openssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428006" comment="xmlsec1-nss is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428007" comment="xmlsec1-nss is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428014" comment="xmlsec1-gnutls is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428015" comment="xmlsec1-gnutls is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428002" comment="xmlsec1 is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428003" comment="xmlsec1 is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428010" comment="xmlsec1-gnutls-devel is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428011" comment="xmlsec1-gnutls-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428008" comment="xmlsec1-openssl-devel is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428009" comment="xmlsec1-openssl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428012" comment="xmlsec1-devel is earlier than 0:1.2.9-8.1.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428013" comment="xmlsec1-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428021" comment="xmlsec1-openssl is earlier than 0:1.2.6-3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428022" comment="xmlsec1-openssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428019" comment="xmlsec1 is earlier than 0:1.2.6-3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428020" comment="xmlsec1 is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428023" comment="xmlsec1-openssl-devel is earlier than 0:1.2.6-3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428024" comment="xmlsec1-openssl-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091428025" comment="xmlsec1-devel is earlier than 0:1.2.6-3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091428026" comment="xmlsec1-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091430" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1430: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1430.html" />
          <reference source="CVE" ref_id="CVE-2009-2654" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2654.html" />
          <reference source="CVE" ref_id="CVE-2009-3070" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3070.html" />
          <reference source="CVE" ref_id="CVE-2009-3071" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3071.html" />
          <reference source="CVE" ref_id="CVE-2009-3072" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3072.html" />
          <reference source="CVE" ref_id="CVE-2009-3074" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3074.html" />
          <reference source="CVE" ref_id="CVE-2009-3075" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3075.html" />
          <reference source="CVE" ref_id="CVE-2009-3076" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3076.html" />
          <reference source="CVE" ref_id="CVE-2009-3077" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3077.html" />
          <reference source="CVE" ref_id="CVE-2009-3078" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3078.html" />
          <reference source="CVE" ref_id="CVE-2009-3079" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3079.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074,
CVE-2009-3075)

A use-after-free flaw was found in Firefox. An attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code with the
privileges of the user running Firefox. (CVE-2009-3077)

A flaw was found in the way Firefox handles malformed JavaScript. A website
with an object containing malicious JavaScript could execute that
JavaScript with the privileges of the user running Firefox. (CVE-2009-3079)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing a trusted site or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3076)

A flaw was found in the way Firefox displays the address bar when
window.open() is called in a certain way. An attacker could use this flaw
to conceal a malicious URL, possibly tricking a user into believing they
are viewing a trusted site. (CVE-2009-2654)

A flaw was found in the way Firefox displays certain Unicode characters. An
attacker could use this flaw to conceal a malicious URL, possibly tricking
a user into believing they are viewing a trusted site. (CVE-2009-3078)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.14. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.14, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-09" />
        <updated date="2009-09-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2654.html">CVE-2009-2654</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3070.html">CVE-2009-3070</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3071.html">CVE-2009-3071</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3072.html">CVE-2009-3072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3074.html">CVE-2009-3074</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3075.html">CVE-2009-3075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3076.html">CVE-2009-3076</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3077.html">CVE-2009-3077</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3078.html">CVE-2009-3078</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3079.html">CVE-2009-3079</cve>
                <bugzilla href="http://bugzilla.redhat.com/521311" id="521311">CVE-2009-2654 firefox: URL bar spoofing vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521686" id="521686">CVE-2009-3070 Firefox 3.5 3.0.14 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521687" id="521687">CVE-2009-3071 Firefox 3.5.2 3.0.14 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521688" id="521688">CVE-2009-3072 Firefox 3.5.3 3.0.14 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521690" id="521690">CVE-2009-3074 Firefox 3.5 3.0.14 JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521691" id="521691">CVE-2009-3075 Firefox 3.5.2 3.0.14 JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521692" id="521692">CVE-2009-3076 Firefox 3.0.14 Insufficient warning for PKCS11 module installation and removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521693" id="521693">CVE-2009-3077 Firefox 3.5.3 3.0.14 TreeColumns dangling pointer vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521694" id="521694">CVE-2009-3078 Firefox 3.5.3 3.0.14 Location bar spoofing via tall line-height Unicode characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521695" id="521695">CVE-2009-3079 Firefox 3.5.3 3.0.14 Chrome privilege escalation with FeedWriter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430006" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.14-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430002" comment="xulrunner is earlier than 0:1.9.0.14-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430004" comment="xulrunner-devel is earlier than 0:1.9.0.14-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430008" comment="firefox is earlier than 0:3.0.14-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430012" comment="nspr-devel is earlier than 0:4.7.5-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091186005" comment="nspr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430010" comment="nspr is earlier than 0:4.7.5-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091186003" comment="nspr is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430015" comment="firefox is earlier than 0:3.0.14-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430019" comment="nspr-devel is earlier than 0:4.7.5-1.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091184011" comment="nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091430017" comment="nspr is earlier than 0:4.7.5-1.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091184009" comment="nspr is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091431" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1431: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1431-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1431.html" />
          <reference source="CVE" ref_id="CVE-2009-2654" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2654.html" />
          <reference source="CVE" ref_id="CVE-2009-3072" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3072.html" />
          <reference source="CVE" ref_id="CVE-2009-3075" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3075.html" />
          <reference source="CVE" ref_id="CVE-2009-3076" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3076.html" />
          <reference source="CVE" ref_id="CVE-2009-3077" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3077.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3072, CVE-2009-3075)

A use-after-free flaw was found in SeaMonkey. An attacker could use this
flaw to crash SeaMonkey or, potentially, execute arbitrary code with the
privileges of the user running SeaMonkey. (CVE-2009-3077)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing a trusted site or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3076)

A flaw was found in the way SeaMonkey displays the address bar when
window.open() is called in a certain way. An attacker could use this flaw
to conceal a malicious URL, possibly tricking a user into believing they
are viewing a trusted site. (CVE-2009-2654)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-09" />
        <updated date="2009-09-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2654.html">CVE-2009-2654</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3072.html">CVE-2009-3072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3075.html">CVE-2009-3075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3076.html">CVE-2009-3076</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3077.html">CVE-2009-3077</cve>
                <bugzilla href="http://bugzilla.redhat.com/521311" id="521311">CVE-2009-2654 firefox: URL bar spoofing vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521688" id="521688">CVE-2009-3072 Firefox 3.5.3 3.0.14 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521691" id="521691">CVE-2009-3075 Firefox 3.5.2 3.0.14 JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521692" id="521692">CVE-2009-3076 Firefox 3.0.14 Insufficient warning for PKCS11 module installation and removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521693" id="521693">CVE-2009-3077 Firefox 3.5.3 3.0.14 TreeColumns dangling pointer vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091431012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-48.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091431010" comment="seamonkey-mail is earlier than 0:1.0.9-48.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091431002" comment="seamonkey is earlier than 0:1.0.9-48.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091431006" comment="seamonkey-devel is earlier than 0:1.0.9-48.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091431004" comment="seamonkey-chat is earlier than 0:1.0.9-48.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091431008" comment="seamonkey-js-debugger is earlier than 0:1.0.9-48.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091432" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1432: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1432-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1432.html" />
          <reference source="CVE" ref_id="CVE-2009-2408" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2408.html" />
          <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html" />
          <reference source="CVE" ref_id="CVE-2009-2654" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2654.html" />
          <reference source="CVE" ref_id="CVE-2009-3072" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3072.html" />
          <reference source="CVE" ref_id="CVE-2009-3075" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3075.html" />
          <reference source="CVE" ref_id="CVE-2009-3076" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3076.html" />
          <reference source="CVE" ref_id="CVE-2009-3077" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3077.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3072, CVE-2009-3075)

A use-after-free flaw was found in SeaMonkey. An attacker could use this
flaw to crash SeaMonkey or, potentially, execute arbitrary code with the
privileges of the user running SeaMonkey. (CVE-2009-3077)

Dan Kaminsky discovered flaws in the way browsers such as SeaMonkey handle
NULL characters in a certificate. If an attacker is able to get a
carefully-crafted certificate signed by a Certificate Authority trusted by
SeaMonkey, the attacker could use the certificate during a
man-in-the-middle attack and potentially confuse SeaMonkey into accepting
it by mistake. (CVE-2009-2408)

Descriptions in the dialogs when adding and removing PKCS #11 modules were
not informative. An attacker able to trick a user into installing a
malicious PKCS #11 module could use this flaw to install their own
Certificate Authority certificates on a user's machine, making it possible
to trick the user into believing they are viewing a trusted site or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3076)

A flaw was found in the way SeaMonkey displays the address bar when
window.open() is called in a certain way. An attacker could use this flaw
to conceal a malicious URL, possibly tricking a user into believing they
are viewing a trusted site. (CVE-2009-2654)

Dan Kaminsky found that browsers still accept certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by a browser. NSS
(provided by SeaMonkey) now disables the use of MD2 and MD4 algorithms
inside signatures by default. (CVE-2009-2409)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-09" />
        <updated date="2009-09-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2408.html">CVE-2009-2408</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2409.html">CVE-2009-2409</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2654.html">CVE-2009-2654</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3072.html">CVE-2009-3072</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3075.html">CVE-2009-3075</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3076.html">CVE-2009-3076</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3077.html">CVE-2009-3077</cve>
                <bugzilla href="http://bugzilla.redhat.com/510197" id="510197">CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/510251" id="510251">CVE-2009-2408 firefox/nss: doesn't handle NULL in Common Name properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521311" id="521311">CVE-2009-2654 firefox: URL bar spoofing vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521688" id="521688">CVE-2009-3072 Firefox 3.5.3 3.0.14 browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521691" id="521691">CVE-2009-3075 Firefox 3.5.2 3.0.14 JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521692" id="521692">CVE-2009-3076 Firefox 3.0.14 Insufficient warning for PKCS11 module installation and removal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521693" id="521693">CVE-2009-3077 Firefox 3.5.3 3.0.14 TreeColumns dangling pointer vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432012" comment="seamonkey-nspr is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432018" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432006" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432016" comment="seamonkey-mail is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432002" comment="seamonkey is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432010" comment="seamonkey-devel is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432014" comment="seamonkey-nss is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432008" comment="seamonkey-chat is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432004" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091432020" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.45.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091438" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1438: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1438-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1438.html" />
          <reference source="CVE" ref_id="CVE-2009-1883" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1883.html" />
          <reference source="CVE" ref_id="CVE-2009-1895" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1895.html" />
          <reference source="CVE" ref_id="CVE-2009-2847" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2847.html" />
          <reference source="CVE" ref_id="CVE-2009-2848" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2848.html" />
          <reference source="CVE" ref_id="CVE-2009-3238" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3238.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security issues:

* the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags were not cleared when a
setuid or setgid program was executed. A local, unprivileged user could use
this flaw to bypass the mmap_min_addr protection mechanism and perform a
NULL pointer dereference attack, or bypass the Address Space Layout
Randomization (ASLR) security feature. (CVE-2009-1895, Important)

* it was discovered that, when executing a new process, the clear_child_tid
pointer in the Linux kernel is not cleared. If this pointer points to a
writable portion of the memory of the new program, the kernel could corrupt
four bytes of memory, possibly leading to a local denial of service or
privilege escalation. (CVE-2009-2848, Important)

* Solar Designer reported a missing capability check in the z90crypt driver
in the Linux kernel. This missing check could allow a local user with an
effective user ID (euid) of 0 to bypass intended capability restrictions.
(CVE-2009-1883, Moderate)

* a flaw was found in the way the do_sigaltstack() function in the Linux
kernel copies the stack_t structure to user-space. On 64-bit machines, this
flaw could lead to a four-byte information leak. (CVE-2009-2847, Moderate)

Bug fixes:

* the gcc flag "-fno-delete-null-pointer-checks" was added to the kernel
build options. This prevents gcc from optimizing out NULL pointer checks
after the first use of a pointer. NULL pointer bugs are often exploited by
attackers. Keeping these checks is a safety measure. (BZ#517964)

* the Emulex LPFC driver has been updated to version 8.0.16.47, which fixes
a memory leak that caused memory allocation failures and system hangs.
(BZ#513192)

* an error in the MPT Fusion driver makefile caused CSMI ioctls to not work
with Serial Attached SCSI devices. (BZ#516184)

* this update adds the mmap_min_addr tunable and restriction checks to help
prevent unprivileged users from creating new memory mappings below the
minimum address. This can help prevent the exploitation of NULL pointer
deference bugs. Note that mmap_min_addr is set to zero (disabled) by
default for backwards compatibility. (BZ#517904)

* time-outs resulted in I/O errors being logged to "/var/log/messages" when
running "mt erase" on tape drives using certain LSI MegaRAID SAS adapters,
preventing the command from completing. The megaraid_sas driver's timeout
value is now set to the OS layer value. (BZ#517965)

* a locking issue caused the qla2xxx ioctl module to hang after
encountering errors. This locking issue has been corrected. This ioctl
module is used by the QLogic SAN management tools, such as SANsurfer and
scli. (BZ#519428)

* when a RAID 1 array that uses the mptscsi driver and the LSI 1030
controller became degraded, the whole array was detected as being offline,
which could cause kernel panics at boot or data loss. (BZ#517295)

* on 32-bit architectures, if a file was held open and frequently written
for more than 25 days, it was possible that the kernel would stop flushing
those writes to storage. (BZ#515255)

* a memory allocation bug in ib_mthca prevented the driver from loading if
it was loaded with large values for the "num_mpt=" and "num_mtt=" options.
See Kbase link below for details. (BZ#518707)

* with this update, get_random_int() is more random and no longer uses a
common seed value, reducing the possibility of predicting the values
returned. See Kbase link below for details. (BZ#519692)

* a bug in __ptrace_unlink() caused it to create deadlocked and unkillable
processes. See Kbase link below for details. (BZ#519446)

* previously, multiple threads using the fcntl() F_SETLK command to
synchronize file access caused a deadlock in posix_locks_deadlock(). This
could cause a system hang. (BZ#519429)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Reboot the system for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-15" />
        <updated date="2009-09-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1883.html">CVE-2009-1883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1895.html">CVE-2009-1895</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2847.html">CVE-2009-2847</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2848.html">CVE-2009-2848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3238.html">CVE-2009-3238</cve>
                <bugzilla href="http://bugzilla.redhat.com/505983" id="505983">CVE-2009-1883 kernel: missing capability check in z90crypt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511171" id="511171">CVE-2009-1895 kernel: personality: fix PER_CLEAR_ON_SETID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/513192" id="513192">[Emulex 4.9 bug] DMA zone exhaustion from lpfc driver memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515255" id="515255">NFS problems on RHEL 4 where logs show different lengths</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515392" id="515392">CVE-2009-2847 kernel: information leak in sigaltstack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515423" id="515423">CVE-2009-2848 kernel: execve: must clear current->clear_child_tid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/516184" id="516184">MPT driver CC_CSMI_SAS_GET_CNTLR_CONFIG IOCTL fails [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517295" id="517295">Missing mptscsi RAID1 disk causes kernel panic when rebooted before array rebuild. [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517904" id="517904">kernel: security: implement mmap_min_addr infrastructure [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517964" id="517964">kernel: build with -fno-delete-null-pointer-checks [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517965" id="517965">MegaRAID SAS 1078 tape I/O errors when using mt erase [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/518707" id="518707">num_mtt settings of 2097152 fails in RHEL with infiniband HCA [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519428" id="519428">[NetApp 4.8 bug] Issues with "qioctlmod" module on RHEL4.8 hosts with QLogic FC inbox drivers [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519429" id="519429">[RHEL 4] Lookups due to infinite loops in posix_locks_deadlock [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519446" id="519446">kernel: ptrace: don't use REMOVE_LINKS/SET_LINKS for reparenting [rhel-4.9] [rhel-4.8.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438002" comment="kernel is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438022" comment="kernel-doc is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438004" comment="kernel-devel is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438014" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438020" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438016" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438012" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438010" comment="kernel-xenU is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438006" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091438008" comment="kernel-smp is earlier than 0:2.6.9-89.0.11.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091451" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1451: freeradius security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1451-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1451.html" />
          <reference source="CVE" ref_id="CVE-2009-3111" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3111.html" />
    
    <description>FreeRADIUS is a high-performance and highly configurable free Remote
Authentication Dial In User Service (RADIUS) server, designed to allow
centralized authentication and authorization for a network.

An input validation flaw was discovered in the way FreeRADIUS decoded
specific RADIUS attributes from RADIUS packets. A remote attacker could use
this flaw to crash the RADIUS daemon (radiusd) via a specially-crafted
RADIUS packet. (CVE-2009-3111)

Users of FreeRADIUS are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, radiusd will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-17" />
        <updated date="2009-09-17" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3111.html">CVE-2009-3111</cve>
                <bugzilla href="http://bugzilla.redhat.com/521912" id="521912">CVE-2009-3111 FreeRADIUS: Missing check for Tunnel-Password attributes with zero length (DoS) -- re-appearance of CVE-2003-0967</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091451004" comment="freeradius-mysql is earlier than 0:1.1.3-1.5.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091451005" comment="freeradius-mysql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091451006" comment="freeradius-postgresql is earlier than 0:1.1.3-1.5.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091451007" comment="freeradius-postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091451008" comment="freeradius-unixODBC is earlier than 0:1.1.3-1.5.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091451009" comment="freeradius-unixODBC is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091451002" comment="freeradius is earlier than 0:1.1.3-1.5.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091451003" comment="freeradius is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091452" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1452: neon security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1452-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1452.html" />
          <reference source="CVE" ref_id="CVE-2009-2473" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2473.html" />
          <reference source="CVE" ref_id="CVE-2009-2474" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2474.html" />
    
    <description>neon is an HTTP and WebDAV client library, with a C interface. It provides
a high-level interface to HTTP and WebDAV methods along with a low-level
interface for HTTP request handling. neon supports persistent connections,
proxy servers, basic, digest and Kerberos authentication, and has complete
SSL support.

It was discovered that neon is affected by the previously published "null
prefix attack", caused by incorrect handling of NULL characters in X.509
certificates. If an attacker is able to get a carefully-crafted certificate
signed by a trusted Certificate Authority, the attacker could use the
certificate during a man-in-the-middle attack and potentially confuse an
application using the neon library into accepting it by mistake.
(CVE-2009-2474)

A denial of service flaw was found in the neon Extensible Markup Language
(XML) parser. A remote attacker (malicious DAV server) could provide a
specially-crafted XML document that would cause excessive memory and CPU
consumption if an application using the neon XML parser was tricked into
processing it. (CVE-2009-2473)

All neon users should upgrade to these updated packages, which contain
backported patches to correct these issues. Applications using the neon
HTTP and WebDAV client library, such as cadaver, must be restarted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-21" />
        <updated date="2009-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2473.html">CVE-2009-2473</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2474.html">CVE-2009-2474</cve>
                <bugzilla href="http://bugzilla.redhat.com/518215" id="518215">CVE-2009-2473 neon, gnome-vfs2 embedded neon: billion laughs DoS attack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/518223" id="518223">CVE-2009-2474 neon: Improper verification of x509v3 certificate with NULL (zero) byte in certain fields</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091452002" comment="neon is earlier than 0:0.25.5-10.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091452003" comment="neon is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091452004" comment="neon-devel is earlier than 0:0.25.5-10.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091452005" comment="neon-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091452007" comment="neon is earlier than 0:0.24.7-4.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091452008" comment="neon is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091452009" comment="neon-devel is earlier than 0:0.24.7-4.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091452010" comment="neon-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091453" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1453: pidgin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1453-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1453.html" />
          <reference source="CVE" ref_id="CVE-2009-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2703.html" />
          <reference source="CVE" ref_id="CVE-2009-3026" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3026.html" />
          <reference source="CVE" ref_id="CVE-2009-3083" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3083.html" />
          <reference source="CVE" ref_id="CVE-2009-3085" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3085.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. Info/Query
(IQ) is an Extensible Messaging and Presence Protocol (XMPP) specific
request-response mechanism.

A NULL pointer dereference flaw was found in the way the Pidgin XMPP
protocol plug-in processes IQ error responses when trying to fetch a custom
smiley. A remote client could send a specially-crafted IQ error response
that would crash Pidgin. (CVE-2009-3085)

A NULL pointer dereference flaw was found in the way the Pidgin IRC
protocol plug-in handles IRC topics. A malicious IRC server could send a
specially-crafted IRC TOPIC message, which once received by Pidgin, would
lead to a denial of service (Pidgin crash). (CVE-2009-2703)

It was discovered that, when connecting to certain, very old Jabber servers
via XMPP, Pidgin may ignore the "Require SSL/TLS" setting. In these
situations, a non-encrypted connection is established rather than the
connection failing, causing the user to believe they are using an encrypted
connection when they are not, leading to sensitive information disclosure
(session sniffing). (CVE-2009-3026)

A NULL pointer dereference flaw was found in the way the Pidgin MSN
protocol plug-in handles improper MSNSLP invitations. A remote attacker
could send a specially-crafted MSNSLP invitation request, which once
accepted by a valid Pidgin user, would lead to a denial of service (Pidgin
crash). (CVE-2009-3083)

These packages upgrade Pidgin to version 2.6.2. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
these issues. Pidgin must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-21" />
        <updated date="2009-09-21" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2703.html">CVE-2009-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3026.html">CVE-2009-3026</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3083.html">CVE-2009-3083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3085.html">CVE-2009-3085</cve>
                <bugzilla href="http://bugzilla.redhat.com/519224" id="519224">CVE-2009-3026 pidgin: ignores SSL/TLS requirements with old jabber servers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521823" id="521823">CVE-2009-2703 Pidgin: NULL pointer dereference by handling IRC topic(s) (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521832" id="521832">CVE-2009-3083 Pidgin: NULL pointer dereference by processing incomplete MSN SLP invite (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521853" id="521853">CVE-2009-3085 Pidgin: NULL pointer dereference by processing a custom smiley (DoS)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453010" comment="libpurple is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060009" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453008" comment="libpurple-perl is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060011" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453004" comment="finch is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060017" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453002" comment="pidgin is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453018" comment="libpurple-devel is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060005" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453016" comment="pidgin-devel is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453014" comment="pidgin-perl is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060013" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453012" comment="finch-devel is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060007" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453006" comment="libpurple-tcl is earlier than 0:2.6.2-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060015" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453037" comment="libpurple is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060030" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453035" comment="finch is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060032" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453027" comment="libpurple-perl is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060038" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453021" comment="pidgin is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453033" comment="libpurple-devel is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060026" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453029" comment="finch-devel is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060034" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453025" comment="pidgin-devel is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060036" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453023" comment="pidgin-perl is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060028" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091453031" comment="libpurple-tcl is earlier than 0:2.6.2-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060024" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091455" version="504" class="patch">
      <metadata>
        <title>RHSA-2009:1455: kernel security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1455-03" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1455.html" />
          <reference source="CVE" ref_id="CVE-2009-2849" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2849.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fix:

* a NULL pointer dereference flaw was found in the Multiple Devices (md)
driver in the Linux kernel. If the "suspend_lo" or "suspend_hi" file on the
sysfs file system ("/sys/") is modified when the disk array is inactive, it
could lead to a local denial of service or privilege escalation. Note: By
default, only the root user can write to the files noted above.
(CVE-2009-2849, Moderate)

Bug fixes:

* a bug in nlm_lookup_host() could lead to un-reclaimed file system locks,
resulting in umount failing &amp; NFS service relocation issues for clusters.
(BZ#517967)

* a bug in the sky2 driver prevented the phy from being reset properly on
some hardware when it hung, preventing a link from coming back up.
(BZ#517976)

* disabling MSI-X for qla2xxx also disabled MSI interrupts. (BZ#519782)

* performance issues with reads when using the qlge driver on PowerPC
systems. A system hang could also occur during reboot. (BZ#519783)

* unreliable time keeping for Red Hat Enterprise Linux virtual machines.
The KVM pvclock code is now used to detect/correct lost ticks. (BZ#520685)

* /proc/cpuinfo was missing flags for new features in supported processors,
possibly preventing the operating system &amp; applications from getting the
best performance. (BZ#520686)

* reading/writing with a serial loopback device on a certain IBM system did
not work unless booted with "pnpacpi=off". (BZ#520905)

* mlx4_core failed to load on systems with more than 32 CPUs. (BZ#520906)

* on big-endian platforms, interfaces using the mlx4_en driver &amp; Large
Receive Offload (LRO) did not handle VLAN traffic properly (a segmentation
fault in the VLAN stack in the kernel occurred). (BZ#520908)

* due to a lock being held for a long time, some systems may have
experienced "BUG: soft lockup" messages under heavy load. (BZ#520919)

* incorrect APIC timer calibration may have caused a system hang during
boot, as well as the system time becoming faster or slower. A warning is
now provided. (BZ#521238)

* a Fibre Channel device re-scan via 'echo "---" > /sys/class/scsi_host/
host[x]/scan' may not complete after hot adding a drive, leading to soft
lockups ("BUG: soft lockup detected"). (BZ#521239)

* the Broadcom BCM5761 network device could not to be initialized
properly; therefore, the associated interface could not obtain an IP
address via DHCP or be assigned one manually. (BZ#521241)

* when a process attempted to read from a page that had first been accessed
by writing to part of it (via write(2)), the NFS client needed to flush the
modified portion of the page out to the server, &amp; then read the entire page
back in. This flush caused performance issues. (BZ#521244)

* a kernel panic when using bnx2x devices &amp; LRO in a bridge. A warning is
now provided to disable LRO in these situations. (BZ#522636)

* the scsi_dh_rdac driver was updated to recognize the Sun StorageTek
Flexline 380. (BZ#523237)

* in FIPS mode, random number generators are required to not return the
first block of random data they generate, but rather save it to seed the
repetition check. This update brings the random number generator into
conformance. (BZ#523289)

* an option to disable/enable the use of the first random block is now
provided to bring ansi_cprng into compliance with FIPS-140 continuous test
requirements. (BZ#523290)

* running the SAP Linux Certification Suite in a KVM guest caused severe
SAP kernel errors, causing it to exit. (BZ#524150)

* attempting to 'online' a CPU for a KVM guest via sysfs caused a system
crash. (BZ#524151)

* when using KVM, pvclock returned bogus wallclock values. (BZ#524152)

* the clock could go backwards when using the vsyscall infrastructure.
(BZ#524527)

See References for KBase links re BZ#519782 &amp; BZ#520906.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Reboot the system for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2010 Red Hat, Inc.</rights>
        <issued date="2009-09-29" />
        <updated date="2010-02-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2849.html">CVE-2009-2849</cve>
                <bugzilla href="http://bugzilla.redhat.com/517967" id="517967">Bug in lockd prevents a locks being freed. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517976" id="517976">[RHEL 5] sky2 eth0: receiver hang detected [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/518132" id="518132">CVE-2009-2849 kernel: md: NULL pointer deref when accessing suspend_* sysfs attributes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519782" id="519782">[QLogic 5.5 bug] qla2xxx - allow use of MSI when MSI-X disabled. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519783" id="519783">[QLogic 5.5 bug] qlge - fix hangs and read perfromance [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520685" id="520685">use KVM pvclock code to detect/correct lost ticks [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520686" id="520686">bare-metal and xen: /proc/cpuinfo does not list all CPU flags presented by CPU [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520905" id="520905">Serial ports don't function on 4838-310 without pnpacpi=off boot option [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520906" id="520906">mlx4_core fails to load on systems with32 cores [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520908" id="520908">TCP traffic for VLAN interfaces fails over mlx4_en parent interface. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520919" id="520919">BUG: soft lockup - CPU#5 stuck for 10s at .context_struct_compute_av+0x214/0x39c [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521238" id="521238">[RHEL 5] Hang on boot due to wrong APIC timer calibration [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521239" id="521239">scsi_transport_fc: fc_user_scan can loop forever, needs mutex with rport list changes [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521241" id="521241">5.4 alpha: Broadcom 5761 NIC does not work [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521244" id="521244">Read/Write NFS I/O performance degraded by FLUSH_STABLE page flushing [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/522636" id="522636">bridge: Fix LRO crash with tun (tun_chr_read()) [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523237" id="523237">Add kernel (scsi_dh_rdac) support for Sun 6540 storage arrays. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523289" id="523289">[FIP140-2] the first n- bit block generated after power-up, initialization, or reset shall not be used [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523290" id="523290">[FIPS140-2] Provide option to disable/enable use of the first random block [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524150" id="524150">Can't override KVM clock in a KVM guest with -165 kernel to triage SAP DB create failure [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524151" id="524151">cpu1 didn't come online in a kvm i686 guest [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524152" id="524152">pvclock return bogus wallclock values [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524527" id="524527">RHEV : SAP SLCS 2.3 fails during install/import in a RHEV-H/KVM guest with PV KVM clock [rhel-5.4.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455004" comment="kernel-headers is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455002" comment="kernel is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455024" comment="kernel-doc is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455020" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455014" comment="kernel-devel is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455012" comment="kernel-debug is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455016" comment="kernel-kdump is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455006" comment="kernel-xen-devel is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455010" comment="kernel-debug-devel is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455022" comment="kernel-PAE is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455018" comment="kernel-kdump-devel is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091455008" comment="kernel-xen is earlier than 0:2.6.18-164.2.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091459" version="505" class="patch">
      <metadata>
        <title>RHSA-2009:1459: cyrus-imapd security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1459-04" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1459.html" />
          <reference source="CVE" ref_id="CVE-2009-2632" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2632.html" />
          <reference source="CVE" ref_id="CVE-2009-3235" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3235.html" />
    
    <description>The cyrus-imapd packages contain a high-performance mail server with IMAP,
POP3, NNTP, and Sieve support.

Multiple buffer overflow flaws were found in the Cyrus IMAP Sieve
implementation. An authenticated user able to create Sieve mail filtering
rules could use these flaws to execute arbitrary code with the privileges
of the Cyrus IMAP server user. (CVE-2009-2632, CVE-2009-3235)

Users of cyrus-imapd are advised to upgrade to these updated packages,
which contain backported patches to resolve these issues. After installing
the update, cyrus-imapd will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-23" />
        <updated date="2009-09-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2632.html">CVE-2009-2632</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3235.html">CVE-2009-3235</cve>
                <bugzilla href="http://bugzilla.redhat.com/521010" id="521010">CVE-2009-2632 cyrus-imapd: buffer overflow in cyrus sieve</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523910" id="523910">CVE-2009-3235 cyrus-impad: CMU sieve buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459008" comment="cyrus-imapd-perl is earlier than 0:2.3.7-7.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116009" comment="cyrus-imapd-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459002" comment="cyrus-imapd is earlier than 0:2.3.7-7.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116003" comment="cyrus-imapd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459006" comment="cyrus-imapd-utils is earlier than 0:2.3.7-7.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116005" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459004" comment="cyrus-imapd-devel is earlier than 0:2.3.7-7.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116007" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459019" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116022" comment="cyrus-imapd-nntp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459017" comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116016" comment="cyrus-imapd-murder is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459011" comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116012" comment="cyrus-imapd is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459021" comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116014" comment="cyrus-imapd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459013" comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116020" comment="cyrus-imapd-utils is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091459015" comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091116018" comment="perl-Cyrus is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091463" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1463: newt security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1463-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1463.html" />
          <reference source="CVE" ref_id="CVE-2009-2905" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2905.html" />
    
    <description>Newt is a programming library for color text mode, widget-based user
interfaces. Newt can be used to add stacked windows, entry widgets,
checkboxes, radio buttons, labels, plain text fields, scrollbars, and so
on, to text mode user interfaces.

A heap-based buffer overflow flaw was found in the way newt processes
content that is to be displayed in a text dialog box. A local attacker
could issue a specially-crafted text dialog box display request (direct or
via a custom application), leading to a denial of service (application
crash) or, potentially, arbitrary code execution with the privileges of the
user running the application using the newt library. (CVE-2009-2905)

Users of newt should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing the updated
packages, all applications using the newt library must be restarted for the
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-24" />
        <updated date="2009-09-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2905.html">CVE-2009-2905</cve>
                <bugzilla href="http://bugzilla.redhat.com/523955" id="523955">CVE-2009-2905 newt: heap-overflow in textbox when text reflowing</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091463004" comment="newt-devel is earlier than 0:0.52.2-12.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091463005" comment="newt-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091463002" comment="newt is earlier than 0:0.52.2-12.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091463003" comment="newt is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091463009" comment="newt-devel is earlier than 0:0.51.5-2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091463010" comment="newt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091463007" comment="newt is earlier than 0:0.51.5-2.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091463008" comment="newt is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091463013" comment="newt-devel is earlier than 0:0.51.6-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091463010" comment="newt-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091463012" comment="newt is earlier than 0:0.51.6-10.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091463008" comment="newt is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091465" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1465: kvm security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1465-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1465.html" />
          <reference source="CVE" ref_id="CVE-2009-3290" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3290.html" />
    
    <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

The kvm_emulate_hypercall() implementation was missing a check for the
Current Privilege Level (CPL). A local, unprivileged user in a virtual
machine could use this flaw to cause a local denial of service or escalate
their privileges within that virtual machine. (CVE-2009-3290)

This update also fixes the following bugs:

* non-maskable interrupts (NMI) were not supported on systems with AMD
processors. As a consequence, Windows Server 2008 R2 guests running with
more than one virtual CPU assigned on systems with AMD processors would
hang at the Windows shut down screen when a restart was attempted. This
update adds support for NMI filtering on systems with AMD processors,
allowing clean restarts of Windows Server 2008 R2 guests running with
multiple virtual CPUs. (BZ#520694)

* significant performance issues for guests running 64-bit editions of
Windows. This update improves performance for guests running 64-bit
editions of Windows. (BZ#521793)

* Windows guests may have experienced time drift. (BZ#521794)

* removing the Red Hat VirtIO Ethernet Adapter from a guest running Windows
Server 2008 R2 caused KVM to crash. With this update, device removal should
not cause this issue. (BZ#524557)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update takes effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-29" />
        <updated date="2009-09-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3290.html">CVE-2009-3290</cve>
                <bugzilla href="http://bugzilla.redhat.com/520694" id="520694">NMI filtering for AMD (Windows 2008 R2 KVM guest can not restart when set it as multiple cpus)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521793" id="521793">windows 64 bit does vmexit on each cr8 access.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521794" id="521794">rtc-td-hack stopped working. Time drifts in windows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524124" id="524124">CVE-2009-3290 kernel: KVM: x86: Disallow hypercalls for guest callers in rings > 0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524557" id="524557">QEMU crash (during virtio-net WHQL tests for Win2008 R2)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091465006" comment="kvm-qemu-img is earlier than 0:83-105.el5_4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465007" comment="kvm-qemu-img is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091465002" comment="kvm is earlier than 0:83-105.el5_4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465003" comment="kvm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091465004" comment="kmod-kvm is earlier than 0:83-105.el5_4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465005" comment="kmod-kvm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091465008" comment="kvm-tools is earlier than 0:83-105.el5_4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465009" comment="kvm-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091470" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1470: openssh security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1470-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1470.html" />
          <reference source="CVE" ref_id="CVE-2009-2904" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2904.html" />
    
    <description>OpenSSH is OpenBSD's SSH (Secure Shell) protocol implementation. These
packages include the core files necessary for both the OpenSSH client and
server.

A Red Hat specific patch used in the openssh packages as shipped in Red
Hat Enterprise Linux 5.4 (RHSA-2009:1287) loosened certain ownership
requirements for directories used as arguments for the ChrootDirectory
configuration options. A malicious user that also has or previously had
non-chroot shell access to a system could possibly use this flaw to
escalate their privileges and run commands as any system user.
(CVE-2009-2904)

All OpenSSH users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing this
update, the OpenSSH server daemon (sshd) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-09-30" />
        <updated date="2009-09-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2904.html">CVE-2009-2904</cve>
                <bugzilla href="http://bugzilla.redhat.com/522141" id="522141">CVE-2009-2904 openssh: possible privilege escalation when using ChrootDirectory setting</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091470002" comment="openssh is earlier than 0:4.3p2-36.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287003" comment="openssh is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091470004" comment="openssh-clients is earlier than 0:4.3p2-36.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287005" comment="openssh-clients is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091470008" comment="openssh-server is earlier than 0:4.3p2-36.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287009" comment="openssh-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091470006" comment="openssh-askpass is earlier than 0:4.3p2-36.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091287007" comment="openssh-askpass is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091471" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1471: elinks security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1471-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1471.html" />
          <reference source="CVE" ref_id="CVE-2007-2027" ref_url="https://www.redhat.com/security/data/cve/CVE-2007-2027.html" />
          <reference source="CVE" ref_id="CVE-2008-7224" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-7224.html" />
    
    <description>ELinks is a text-based Web browser. ELinks does not display any images, but
it does support frames, tables, and most other HTML tags.

An off-by-one buffer overflow flaw was discovered in the way ELinks handled
its internal cache of string representations for HTML special entities. A
remote attacker could use this flaw to create a specially-crafted HTML file
that would cause ELinks to crash or, possibly, execute arbitrary code when
rendered. (CVE-2008-7224)

It was discovered that ELinks tried to load translation files using
relative paths. A local attacker able to trick a victim into running ELinks
in a folder containing specially-crafted translation files could use this
flaw to confuse the victim via incorrect translations, or cause ELinks to
crash and possibly execute arbitrary code via embedded formatting sequences
in translated messages. (CVE-2007-2027)

All ELinks users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-01" />
        <updated date="2009-10-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2007-2027.html">CVE-2007-2027</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-7224.html">CVE-2008-7224</cve>
                <bugzilla href="http://bugzilla.redhat.com/235411" id="235411">CVE-2007-2027 elinks tries to load .po files from a non-absolute path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523258" id="523258">CVE-2008-7224 elinks: entity_cache static array buffer overflow (off-by-one)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091471002" comment="elinks is earlier than 0:0.11.1-6.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091471003" comment="elinks is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091471005" comment="elinks is earlier than 0:0.9.2-4.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091471006" comment="elinks is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091472" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1472: xen security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1472-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1472.html" />
          <reference source="CVE" ref_id="CVE-2009-3525" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3525.html" />
    
    <description>Xen is an open source virtualization framework. Virtualization allows users
to run guest operating systems in virtual machines on top of a host
operating system.

The pyGrub boot loader did not honor the "password" option in the grub.conf
file for para-virtualized guests. Users with access to a guest's console
could use this flaw to bypass intended access restrictions and boot the
guest with arbitrary kernel boot options, allowing them to get root
privileges in the guest's operating system. With this update, pyGrub
correctly honors the "password" option in grub.conf for para-virtualized
guests. (CVE-2009-3525)

This update also fixes the following bugs:

* rebooting para-virtualized guests sometimes caused those guests to crash
due to a race condition in the xend node control daemon. This update fixes
this race condition so that rebooting guests no longer potentially causes
them to crash and fail to reboot. (BZ#525141)

* due to a race condition in the xend daemon, a guest could disappear from
the list of running guests following a reboot, even though the guest
rebooted successfully and was running. This update fixes this race
condition so that guests always reappear in the guest list following a
reboot. (BZ#525143)

* attempting to use PCI pass-through to para-virtualized guests on certain
kernels failed with a "Function not implemented" error message. As a
result, users requiring PCI pass-through on para-virtualized guests were
not able to update the xen packages without also updating the kernel and
thus requiring a reboot. These updated packages enable PCI pass-through for
para-virtualized guests so that users do not need to upgrade the kernel in
order to take advantage of PCI pass-through functionality. (BZ#525149)

All Xen users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the xend service must be restarted for this update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-01" />
        <updated date="2009-10-01" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3525.html">CVE-2009-3525</cve>
                <bugzilla href="http://bugzilla.redhat.com/525141" id="525141">[REG][Xen][5.4] PV domains may crash after reboot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525142" id="525142">Add grub.conf password protection support to pygrub</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525143" id="525143">Domain goes missing from xm list when rebooted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525149" id="525149">PCI-Paththrough with PCI-Card does not work anymore with RHEL5.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525740" id="525740">CVE-2009-3525 Xen: PyGrub missing support for password configuration command</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091472002" comment="xen is earlier than 0:3.0.3-94.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003003" comment="xen is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091472004" comment="xen-libs is earlier than 0:3.0.3-94.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003005" comment="xen-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091472006" comment="xen-devel is earlier than 0:3.0.3-94.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003007" comment="xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091484" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1484: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1484-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1484.html" />
          <reference source="CVE" ref_id="CVE-2009-0922" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0922.html" />
          <reference source="CVE" ref_id="CVE-2009-3230" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3230.html" />
    
    <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

It was discovered that the upstream patch for CVE-2007-6600 included in the
Red Hat Security Advisory RHSA-2008:0038 did not include protection against
misuse of the RESET ROLE and RESET SESSION AUTHORIZATION commands. An
authenticated user could use this flaw to install malicious code that would
later execute with superuser privileges. (CVE-2009-3230)

A flaw was found in the way PostgreSQL handled encoding conversion. A
remote, authenticated user could trigger an encoding conversion failure,
possibly leading to a temporary denial of service. Note: To exploit this
issue, a locale and client encoding for which specific messages fail to
translate must be selected (the availability of these is determined by an
administrator-defined locale setting). (CVE-2009-0922)

Note: For Red Hat Enterprise Linux 4, this update upgrades PostgreSQL to
version 7.4.26. For Red Hat Enterprise Linux 5, this update upgrades
PostgreSQL to version 8.1.18. Refer to the PostgreSQL Release Notes for a
list of changes:

http://www.postgresql.org/docs/7.4/static/release.html
http://www.postgresql.org/docs/8.1/static/release.html

All PostgreSQL users should upgrade to these updated packages, which
resolve these issues. If the postgresql service is running, it will be
automatically restarted after installing this update.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-07" />
        <updated date="2009-10-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0922.html">CVE-2009-0922</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3230.html">CVE-2009-3230</cve>
                <bugzilla href="http://bugzilla.redhat.com/488156" id="488156">CVE-2009-0922 postgresql: potential DoS due to conversion functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/522085" id="522085">CVE-2009-3230 postgresql: SQL privilege escalation, incomplete fix for CVE-2007-6600</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484010" comment="postgresql-docs is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484011" comment="postgresql-docs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484016" comment="postgresql-devel is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484017" comment="postgresql-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484006" comment="postgresql-contrib is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484007" comment="postgresql-contrib is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484004" comment="postgresql-test is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484005" comment="postgresql-test is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484012" comment="postgresql-libs is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484013" comment="postgresql-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484014" comment="postgresql-tcl is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484015" comment="postgresql-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484002" comment="postgresql is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484003" comment="postgresql is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484020" comment="postgresql-pl is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484021" comment="postgresql-pl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484018" comment="postgresql-server is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484019" comment="postgresql-server is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484008" comment="postgresql-python is earlier than 0:8.1.18-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484009" comment="postgresql-python is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484041" comment="postgresql-jdbc is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484042" comment="postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484029" comment="postgresql-docs is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484030" comment="postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484033" comment="postgresql-devel is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484034" comment="postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484039" comment="postgresql-test is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484040" comment="postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484031" comment="postgresql-contrib is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484032" comment="postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484043" comment="postgresql-libs is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484044" comment="postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484025" comment="postgresql-tcl is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484026" comment="postgresql-tcl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484023" comment="postgresql is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484024" comment="postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484037" comment="postgresql-python is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484038" comment="postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484035" comment="postgresql-server is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484036" comment="postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091484027" comment="postgresql-pl is earlier than 0:7.4.26-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091484028" comment="postgresql-pl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091485" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1485: postgresql security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1485-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1485.html" />
          <reference source="CVE" ref_id="CVE-2009-3230" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3230.html" />
    
    <description>PostgreSQL is an advanced object-relational database management system
(DBMS).

It was discovered that the upstream patch for CVE-2007-6600 included in the
Red Hat Security Advisory RHSA-2008:0039 did not include protection against
misuse of the RESET ROLE and RESET SESSION AUTHORIZATION commands. An
authenticated user could use this flaw to install malicious code that would
later execute with superuser privileges. (CVE-2009-3230)

All PostgreSQL users should upgrade to these updated packages, which
contain a backported patch to correct this issue. If you are running a
PostgreSQL server, the postgresql service must be restarted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-07" />
        <updated date="2009-10-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3230.html">CVE-2009-3230</cve>
                <bugzilla href="http://bugzilla.redhat.com/522085" id="522085">CVE-2009-3230 postgresql: SQL privilege escalation, incomplete fix for CVE-2007-6600</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485016" comment="rh-postgresql-docs is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485017" comment="rh-postgresql-docs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485006" comment="rh-postgresql-jdbc is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485007" comment="rh-postgresql-jdbc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485014" comment="rh-postgresql-contrib is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485015" comment="rh-postgresql-contrib is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485002" comment="rh-postgresql is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485003" comment="rh-postgresql is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485020" comment="rh-postgresql-pl is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485021" comment="rh-postgresql-pl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485018" comment="rh-postgresql-python is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485019" comment="rh-postgresql-python is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485010" comment="rh-postgresql-devel is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485011" comment="rh-postgresql-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485022" comment="rh-postgresql-test is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485023" comment="rh-postgresql-test is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485012" comment="rh-postgresql-libs is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485013" comment="rh-postgresql-libs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485008" comment="rh-postgresql-server is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485009" comment="rh-postgresql-server is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091485004" comment="rh-postgresql-tcl is earlier than 0:7.3.21-2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091485005" comment="rh-postgresql-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091490" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1490: squirrelmail security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1490-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1490.html" />
          <reference source="CVE" ref_id="CVE-2009-2964" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2964.html" />
    
    <description>SquirrelMail is a standards-based webmail package written in PHP.

Form submissions in SquirrelMail did not implement protection against
Cross-Site Request Forgery (CSRF) attacks. If a remote attacker tricked a
user into visiting a malicious web page, the attacker could hijack that
user's authentication, inject malicious content into that user's
preferences, or possibly send mail without that user's permission.
(CVE-2009-2964)

Users of SquirrelMail should upgrade to this updated package, which
contains a backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-08" />
        <updated date="2009-10-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2964.html">CVE-2009-2964</cve>
                <bugzilla href="http://bugzilla.redhat.com/517312" id="517312">CVE-2009-2964 squirrelmail: CSRF issues in all forms</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091490002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_4.10" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091490005" comment="squirrelmail is earlier than 0:1.4.8-16.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091490008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091499" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1499: acroread security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1499-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1499.html" />
          <reference source="CVE" ref_id="CVE-2009-2979" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2979.html" />
          <reference source="CVE" ref_id="CVE-2009-2980" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2980.html" />
          <reference source="CVE" ref_id="CVE-2009-2981" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2981.html" />
          <reference source="CVE" ref_id="CVE-2009-2983" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2983.html" />
          <reference source="CVE" ref_id="CVE-2009-2985" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2985.html" />
          <reference source="CVE" ref_id="CVE-2009-2986" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2986.html" />
          <reference source="CVE" ref_id="CVE-2009-2988" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2988.html" />
          <reference source="CVE" ref_id="CVE-2009-2990" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2990.html" />
          <reference source="CVE" ref_id="CVE-2009-2991" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2991.html" />
          <reference source="CVE" ref_id="CVE-2009-2993" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2993.html" />
          <reference source="CVE" ref_id="CVE-2009-2994" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2994.html" />
          <reference source="CVE" ref_id="CVE-2009-2996" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2996.html" />
          <reference source="CVE" ref_id="CVE-2009-2997" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2997.html" />
          <reference source="CVE" ref_id="CVE-2009-2998" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2998.html" />
          <reference source="CVE" ref_id="CVE-2009-3431" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3431.html" />
          <reference source="CVE" ref_id="CVE-2009-3458" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3458.html" />
          <reference source="CVE" ref_id="CVE-2009-3459" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3459.html" />
          <reference source="CVE" ref_id="CVE-2009-3462" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3462.html" />
    
    <description>Adobe Reader allows users to view and print documents in Portable Document
Format (PDF).

Multiple flaws were discovered in Adobe Reader. A specially-crafted PDF
file could cause Adobe Reader to crash or, potentially, execute arbitrary
code as the user running Adobe Reader when opened. (CVE-2009-2980,
CVE-2009-2983, CVE-2009-2985, CVE-2009-2986, CVE-2009-2990, CVE-2009-2991,
CVE-2009-2993, CVE-2009-2994, CVE-2009-2996, CVE-2009-2997, CVE-2009-2998,
CVE-2009-3458, CVE-2009-3459, CVE-2009-3462)

Multiple flaws were discovered in Adobe Reader. A specially-crafted PDF
file could cause Adobe Reader to crash when opened. (CVE-2009-2979,
CVE-2009-2988, CVE-2009-3431)

An input validation flaw was found in Adobe Reader. Opening a
specially-crafted PDF file could lead to a Trust Manager restrictions
bypass. (CVE-2009-2981)

All Adobe Reader users should install these updated packages. They contain
Adobe Reader version 8.1.7, which is not vulnerable to these issues. All
running instances of Adobe Reader must be restarted for the update to take
effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-14" />
        <updated date="2009-10-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2979.html">CVE-2009-2979</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2980.html">CVE-2009-2980</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2981.html">CVE-2009-2981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2983.html">CVE-2009-2983</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2985.html">CVE-2009-2985</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2986.html">CVE-2009-2986</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2988.html">CVE-2009-2988</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2990.html">CVE-2009-2990</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2991.html">CVE-2009-2991</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2993.html">CVE-2009-2993</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2994.html">CVE-2009-2994</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2996.html">CVE-2009-2996</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2997.html">CVE-2009-2997</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2998.html">CVE-2009-2998</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3431.html">CVE-2009-3431</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3458.html">CVE-2009-3458</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3459.html">CVE-2009-3459</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3462.html">CVE-2009-3462</cve>
                <bugzilla href="http://bugzilla.redhat.com/528071" id="528071">CVE-2009-3459 acroread: heap overflow fix in version 8.1.7 (APSB09-15)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528659" id="528659">acroread: Multiple arbitrary code execution fixes in 8.1.7 (APSB09-15)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528665" id="528665">CVE-2009-2979 CVE-2009-2988 CVE-2009-3431 acroread: Multiple DoS fixes in 8.1.7 (APSB09-15)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528666" id="528666">CVE-2009-2981 acroread: Trust Manager restrictions bypass fixed in 8.1.7 (APSB09-15)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091499004" comment="acroread-plugin is earlier than 0:8.1.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376005" comment="acroread-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091499002" comment="acroread is earlier than 0:8.1.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090376003" comment="acroread is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091500" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1500: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1500-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1500.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-3604" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3604.html" />
          <reference source="CVE" ref_id="CVE-2009-3606" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3606.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in Xpdf. An attacker could
create a malicious PDF file that would cause Xpdf to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-3604,
CVE-2009-3606, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3604.html">CVE-2009-3604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3606.html">CVE-2009-3606</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 xpdf: multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526877" id="526877">CVE-2009-3606 xpdf/poppler: PSOutputDev::doImageL1Sep integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526911" id="526911">CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091500002" comment="xpdf is earlier than 1:2.02-17.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091501" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1501: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1501-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1501.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1188.html" />
          <reference source="CVE" ref_id="CVE-2009-3604" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3604.html" />
          <reference source="CVE" ref_id="CVE-2009-3606" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3606.html" />
          <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in Xpdf. An attacker could
create a malicious PDF file that would cause Xpdf to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3606, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1188.html">CVE-2009-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3604.html">CVE-2009-3604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3606.html">CVE-2009-3606</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3608.html">CVE-2009-3608</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 xpdf: multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495907" id="495907">CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526637" id="526637">CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526877" id="526877">CVE-2009-3606 xpdf/poppler: PSOutputDev::doImageL1Sep integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526911" id="526911">CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091501002" comment="xpdf is earlier than 1:3.00-22.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091502" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1502: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1502-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1502.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1188.html" />
          <reference source="CVE" ref_id="CVE-2009-3604" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3604.html" />
          <reference source="CVE" ref_id="CVE-2009-3606" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3606.html" />
          <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF. An attacker could
create a malicious PDF file that would cause KPDF to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3606, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to these updated packages, which contain a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1188.html">CVE-2009-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3604.html">CVE-2009-3604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3606.html">CVE-2009-3606</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3608.html">CVE-2009-3608</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 xpdf: multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495907" id="495907">CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526637" id="526637">CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526877" id="526877">CVE-2009-3606 xpdf/poppler: PSOutputDev::doImageL1Sep integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526911" id="526911">CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091502002" comment="kdegraphics is earlier than 7:3.5.4-15.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431003" comment="kdegraphics is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091502004" comment="kdegraphics-devel is earlier than 7:3.5.4-15.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431005" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091503" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1503: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1503-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1503.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1188.html" />
          <reference source="CVE" ref_id="CVE-2009-3604" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3604.html" />
          <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>GPdf is a viewer for Portable Document Format (PDF) files.

Multiple integer overflow flaws were found in GPdf. An attacker could
create a malicious PDF file that would cause GPdf to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1188.html">CVE-2009-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3604.html">CVE-2009-3604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3608.html">CVE-2009-3608</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 xpdf: multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495907" id="495907">CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526637" id="526637">CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526911" id="526911">CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091503002" comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090458003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091504" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1504: poppler security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1504-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1504.html" />
          <reference source="CVE" ref_id="CVE-2009-3603" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3603.html" />
          <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-3603, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608
issue.

This update also corrects a regression introduced in the previous poppler
security update, RHSA-2009:0480, that prevented poppler from rendering
certain PDF documents correctly. (BZ#528147)

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3603.html">CVE-2009-3603</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3608.html">CVE-2009-3608</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/526637" id="526637">CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526915" id="526915">CVE-2009-3603 xpdf/poppler: SplashBitmap::SplashBitmap integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528147" id="528147">latest poppler security fix breaks compatibility with Xerox WorkCentre generated pdf documents</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091504006" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_4.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480007" comment="poppler-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091504002" comment="poppler is earlier than 0:0.5.4-4.4.el5_4.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480003" comment="poppler is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091504004" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_4.11" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480005" comment="poppler-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091505" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1505: java-1.4.2-ibm security update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1505-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1505.html" />
          <reference source="CVE" ref_id="CVE-2008-5349" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5349.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
    
    <description>The IBM 1.4.2 SR13-FP1 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

This update fixes two vulnerabilities in the IBM Java 2 Runtime Environment
and the IBM Java 2 Software Development Kit. These vulnerabilities are
summarized on the IBM "Security alerts" page listed in the References
section. (CVE-2008-5349, CVE-2009-2625)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13-FP1 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-14" />
        <updated date="2009-10-14" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5349.html">CVE-2008-5349</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
                <bugzilla href="http://bugzilla.redhat.com/472206" id="472206">CVE-2008-5349 OpenJDK RSA public key length denial-of-service (6497740)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505008" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445005" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505012" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505010" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505004" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445009" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091505006" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.1-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445007" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091512" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1512: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1512-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1512.html" />
          <reference source="CVE" ref_id="CVE-2009-0791" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0791.html" />
          <reference source="CVE" ref_id="CVE-2009-1188" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1188.html" />
          <reference source="CVE" ref_id="CVE-2009-3604" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3604.html" />
          <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF. An attacker could
create a malicious PDF file that would cause KPDF to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0791, CVE-2009-1188,
CVE-2009-3604, CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Adam Zabrocki for reporting the CVE-2009-3604
issue, and Chris Rohlf for reporting the CVE-2009-3608 issue.

Users are advised to upgrade to these updated packages, which contain a
backported patch to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0791.html">CVE-2009-0791</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1188.html">CVE-2009-1188</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3604.html">CVE-2009-3604</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3608.html">CVE-2009-3608</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 xpdf: multiple integer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495907" id="495907">CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526637" id="526637">CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526911" id="526911">CVE-2009-3604 xpdf/poppler: Splash::drawImage integer overflow and missing allocation return value check</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091512002" comment="kdegraphics is earlier than 7:3.3.1-15.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431008" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091512004" comment="kdegraphics-devel is earlier than 7:3.3.1-15.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431010" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091513" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1513: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1513-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1513.html" />
          <reference source="CVE" ref_id="CVE-2009-3608" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3608.html" />
          <reference source="CVE" ref_id="CVE-2009-3609" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3609.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The CUPS "pdftops" filter converts Portable
Document Format (PDF) files to PostScript.

Two integer overflow flaws were found in the CUPS "pdftops" filter. An
attacker could create a malicious PDF file that would cause "pdftops" to
crash or, potentially, execute arbitrary code as the "lp" user if the file
was printed. (CVE-2009-3608, CVE-2009-3609)

Red Hat would like to thank Chris Rohlf for reporting the CVE-2009-3608
issue.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-15" />
        <updated date="2009-10-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3608.html">CVE-2009-3608</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3609.html">CVE-2009-3609</cve>
                <bugzilla href="http://bugzilla.redhat.com/526637" id="526637">CVE-2009-3608 xpdf/poppler: integer overflow in ObjectStream::ObjectStream (oCERT-2009-016)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526893" id="526893">CVE-2009-3609 xpdf/poppler: ImageStream::ImageStream integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091513008" comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091513004" comment="cups-devel is earlier than 1:1.3.7-11.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091513006" comment="cups-libs is earlier than 1:1.3.7-11.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091513002" comment="cups is earlier than 1:1.3.7-11.el5_4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091522" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1522: kernel security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1522-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1522.html" />
          <reference source="CVE" ref_id="CVE-2005-4881" ref_url="https://www.redhat.com/security/data/cve/CVE-2005-4881.html" />
          <reference source="CVE" ref_id="CVE-2009-3228" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3228.html" />
          <reference source="CVE" ref_id="CVE-2009-3612" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3612.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* multiple, missing initialization flaws were found in the Linux kernel.
Padding data in several core network structures was not initialized
properly before being sent to user-space. These flaws could lead to
information leaks. (CVE-2005-4881, CVE-2009-3228, Moderate)

This update also fixes the following bugs:

* a packet duplication issue was fixed via the RHSA-2008:0665 update;
however, the fix introduced a problem for systems using network bonding:
Backup slaves were unable to receive ARP packets. When using network
bonding in the "active-backup" mode and with the "arp_validate=3" option,
the bonding driver considered such backup slaves as being down (since they
were not receiving ARP packets), preventing successful failover to these
devices. (BZ#519384)

* due to insufficient memory barriers in the network code, a process
sleeping in select() may have missed notifications about new data. In rare
cases, this bug may have caused a process to sleep forever. (BZ#519386)

* the driver version number in the ata_piix driver was not changed between
Red Hat Enterprise Linux 4.7 and Red Hat Enterprise Linux 4.8, even though
changes had been made between these releases. This could have prevented the
driver from loading on systems that check driver versions, as this driver
appeared older than it was. (BZ#519389)

* a bug in nlm_lookup_host() could have led to un-reclaimed locks on file
systems, resulting in the umount command failing. This bug could have also
prevented NFS services from being relocated correctly in clustered
environments. (BZ#519656)

* the data buffer ethtool_get_strings() allocated, for the igb driver, was
smaller than the amount of data that was copied in igb_get_strings(),
because of a miscalculation in IGB_QUEUE_STATS_LEN, resulting in memory
corruption. This bug could have led to a kernel panic. (BZ#522738)

* in some circumstances, write operations to a particular TTY device opened
by more than one user (eg, one opened it as /dev/console and the other
opened it as /dev/ttyS0) were blocked. If one user opened the TTY terminal
without setting the O_NONBLOCK flag, this user's write operations were
suspended if the output buffer was full or if a STOP (Ctrl-S) signal was
sent. As well, because the O_NONBLOCK flag was not respected, Write
operations for user terminals opened with the O_NONBLOCK flag set were also
blocked. This update re-implements TTY locks, ensuring O_NONBLOCK works as
expected, even if it a STOP signal is sent from another terminal.
(BZ#523930)

* a deadlock was found in the cciss driver. In rare cases, this caused an
NMI lockup during boot. Messages such as "cciss: controller cciss[x]
failed, stopping." and "cciss[x]: controller not responding." may have
been displayed on the console. (BZ#525725)

* on 64-bit PowerPC systems, a rollover bug in the ibmveth driver could
have caused a kernel panic. In a reported case, this panic occurred on a
system with a large uptime and under heavy network load. (BZ#527225)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-22" />
        <updated date="2009-10-22" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2005-4881.html">CVE-2005-4881</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3228.html">CVE-2009-3228</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3612.html">CVE-2009-3612</cve>
                <bugzilla href="http://bugzilla.redhat.com/519384" id="519384">[RHEL 4] Arp Monitor - Failed to detect layer 2 switch failure [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519386" id="519386">[RHEL4.5] Even if a process have received data but schedule() in select() cannot return [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519389" id="519389">RHEL4.8-Beta : Update the version number of ata_piix driver [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519656" id="519656">Bug in lockd prevents a locks being freed. [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520990" id="520990">CVE-2009-3228 kernel: tc: uninitialised kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521601" id="521601">CVE-2005-4881 kernel: netlink: fix numerous padding memleaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/522738" id="522738">[RHEL4.8] igb driver doesn't allocate enough buffer for ethtool_get_strings() [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523930" id="523930">[4.8]Write operation with O_NONBLOCK flag to TTY terminal is blocked [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/525725" id="525725">cciss: spinlock deadlock causes NMI on HP systems [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/527225" id="527225">BUG in ibmveth_replenish_buffer_pool at drivers/net/ibmveth.c:219 [rhel-4.8.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522002" comment="kernel is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522022" comment="kernel-doc is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522004" comment="kernel-devel is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522010" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522018" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522016" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522014" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522012" comment="kernel-xenU is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091522006" comment="kernel-smp is earlier than 0:2.6.9-89.0.15.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091526" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1526: Red Hat Enterprise Linux 3 - 1-Year End Of Life Notice (Low)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1526-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1526.html" />
    
    <description>In accordance with the Red Hat Enterprise Linux Errata Support Policy, the
regular 7 year life-cycle of Red Hat Enterprise Linux 3 will end on October
31, 2010.

After this date, Red Hat will discontinue the regular subscription services
for Red Hat Enterprise Linux 3. Therefore, new bug fix, enhancement, and
security errata updates, as well as technical support services will no
longer be available for the following products:

* Red Hat Enterprise Linux AS 3
* Red Hat Enterprise Linux ES 3
* Red Hat Enterprise Linux WS 3
* Red Hat Enterprise Linux Extras 3
* Red Hat Desktop 3
* Red Hat Global File System 3
* Red Hat Cluster Suite 3

Customers still running production workloads on Red Hat Enterprise
Linux 3 are advised to begin planning the upgrade to Red Hat Enterprise
Linux 5. Active subscribers of Red Hat Enterprise Linux already have access
to all currently maintained versions of Red Hat Enterprise Linux, as part
of their subscription without additional fees.

For customers who are unable to migrate off Red Hat Enterprise Linux 3
before its end-of-life date, Red Hat may offer a limited, optional
extension program. For more information, contact your Red Hat sales
representative or channel partner.

Details of the Red Hat Enterprise Linux life-cycle can be found on the Red
Hat website: http://www.redhat.com/security/updates/errata/</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-09" />
        <updated date="2009-11-09" />
                <bugzilla href="http://bugzilla.redhat.com/531220" id="531220">Send Out RHEL 3 1-Year EOL Notice</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091526002" comment="redhat-release is earlier than 0:3Desktop-13.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091526003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091526004" comment="redhat-release is earlier than 0:3WS-13.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091526003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091526005" comment="redhat-release is earlier than 0:3ES-13.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091526003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091526006" comment="redhat-release is earlier than 0:3AS-13.9.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091526003" comment="redhat-release is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091528" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1528: samba security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1528-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1528.html" />
          <reference source="CVE" ref_id="CVE-2009-2906" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2906.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A denial of service flaw was found in the Samba smbd daemon. An
authenticated, remote user could send a specially-crafted response that
would cause an smbd child process to enter an infinite loop. An
authenticated, remote user could use this flaw to exhaust system resources
by opening multiple CIFS sessions. (CVE-2009-2906)

This update also fixes the following bug:

* the RHSA-2007:0354 update added code to escape input passed to scripts
that are run by Samba. This code was missing "c" from the list of valid
characters, causing it to be escaped. With this update, the previous patch
has been updated to include "c" in the list of valid characters.
(BZ#242754)

Users of Samba should upgrade to these updated packages, which contain a
backported patch to correct this issue. After installing this update,
the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-27" />
        <updated date="2009-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2906.html">CVE-2009-2906</cve>
                <bugzilla href="http://bugzilla.redhat.com/242754" id="242754">Missing character bug in latest security patches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526645" id="526645">CVE-2009-2906 samba: infinite loop flaw in smbd on unexpected oplock break notification reply</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091528008" comment="samba-client is earlier than 0:3.0.9-1.3E.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528009" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091528004" comment="samba-common is earlier than 0:3.0.9-1.3E.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528005" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091528002" comment="samba is earlier than 0:3.0.9-1.3E.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091528006" comment="samba-swat is earlier than 0:3.0.9-1.3E.16" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528007" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091529" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1529: samba security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1529-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1529.html" />
          <reference source="CVE" ref_id="CVE-2009-1888" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1888.html" />
          <reference source="CVE" ref_id="CVE-2009-2813" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2813.html" />
          <reference source="CVE" ref_id="CVE-2009-2906" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2906.html" />
          <reference source="CVE" ref_id="CVE-2009-2948" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2948.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information.

A denial of service flaw was found in the Samba smbd daemon. An
authenticated, remote user could send a specially-crafted response that
would cause an smbd child process to enter an infinite loop. An
authenticated, remote user could use this flaw to exhaust system resources
by opening multiple CIFS sessions. (CVE-2009-2906)

An uninitialized data access flaw was discovered in the smbd daemon when
using the non-default "dos filemode" configuration option in "smb.conf". An
authenticated, remote user with write access to a file could possibly use
this flaw to change an access control list for that file, even when such
access should have been denied. (CVE-2009-1888)

A flaw was discovered in the way Samba handled users without a home
directory set in the back-end password database (e.g. "/etc/passwd"). If a
share for the home directory of such a user was created (e.g. using the
automated "[homes]" share), any user able to access that share could see
the whole file system, possibly bypassing intended access restrictions.
(CVE-2009-2813)

The mount.cifs program printed CIFS passwords as part of its debug output
when running in verbose mode. When mount.cifs had the setuid bit set, a
local, unprivileged user could use this flaw to disclose passwords from a
file that would otherwise be inaccessible to that user. Note: mount.cifs
from the samba packages distributed by Red Hat does not have the setuid bit
set. This flaw only affected systems where the setuid bit was manually set
by an administrator. (CVE-2009-2948)

Users of Samba should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing this update,
the smb service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-27" />
        <updated date="2009-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1888.html">CVE-2009-1888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2813.html">CVE-2009-2813</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2906.html">CVE-2009-2906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2948.html">CVE-2009-2948</cve>
                <bugzilla href="http://bugzilla.redhat.com/506996" id="506996">CVE-2009-1888 Samba improper file access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523752" id="523752">CVE-2009-2813 Samba: Share restriction bypass via home-less directory user account(s)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526074" id="526074">CVE-2009-2948 samba: information disclosure in suid mount.cifs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526645" id="526645">CVE-2009-2906 samba: infinite loop flaw in smbd on unexpected oplock break notification reply</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529006" comment="samba-client is earlier than 0:3.0.33-3.15.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091529007" comment="samba-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529008" comment="samba-common is earlier than 0:3.0.33-3.15.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091529009" comment="samba-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529002" comment="samba is earlier than 0:3.0.33-3.15.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091529003" comment="samba is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529004" comment="samba-swat is earlier than 0:3.0.33-3.15.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091529005" comment="samba-swat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529013" comment="samba-client is earlier than 0:3.0.33-0.18.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528009" comment="samba-client is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529017" comment="samba-common is earlier than 0:3.0.33-0.18.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528005" comment="samba-common is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529011" comment="samba is earlier than 0:3.0.33-0.18.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528003" comment="samba is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091529015" comment="samba-swat is earlier than 0:3.0.33-0.18.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091528007" comment="samba-swat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091530" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1530: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1530-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1530.html" />
          <reference source="CVE" ref_id="CVE-2009-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1563.html" />
          <reference source="CVE" ref_id="CVE-2009-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3274.html" />
          <reference source="CVE" ref_id="CVE-2009-3370" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3370.html" />
          <reference source="CVE" ref_id="CVE-2009-3372" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3372.html" />
          <reference source="CVE" ref_id="CVE-2009-3373" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3373.html" />
          <reference source="CVE" ref_id="CVE-2009-3374" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3374.html" />
          <reference source="CVE" ref_id="CVE-2009-3375" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3375.html" />
          <reference source="CVE" ref_id="CVE-2009-3376" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3376.html" />
          <reference source="CVE" ref_id="CVE-2009-3380" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3380.html" />
          <reference source="CVE" ref_id="CVE-2009-3382" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3382.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox. nspr provides the Netscape
Portable Runtime (NSPR).

A flaw was found in the way Firefox handles form history. A malicious web
page could steal saved form data by synthesizing input events, causing the
browser to auto-fill form fields (which could then be read by an attacker).
(CVE-2009-3370)

A flaw was found in the way Firefox creates temporary file names for
downloaded files. If a local attacker knows the name of a file Firefox is
going to download, they can replace the contents of that file with
arbitrary contents. (CVE-2009-3274)

A flaw was found in the Firefox Proxy Auto-Configuration (PAC) file
processor. If Firefox loads a malicious PAC file, it could crash Firefox
or, potentially, execute arbitrary code with the privileges of the user
running Firefox. (CVE-2009-3372)

A heap-based buffer overflow flaw was found in the Firefox GIF image
processor. A malicious GIF image could crash Firefox or, potentially,
execute arbitrary code with the privileges of the user running Firefox.
(CVE-2009-3373)

A heap-based buffer overflow flaw was found in the Firefox string to
floating point conversion routines. A web page containing malicious
JavaScript could crash Firefox or, potentially, execute arbitrary code with
the privileges of the user running Firefox. (CVE-2009-1563)

A flaw was found in the way Firefox handles text selection. A malicious
website may be able to read highlighted text in a different domain (e.g.
another website the user is viewing), bypassing the same-origin policy.
(CVE-2009-3375)

A flaw was found in the way Firefox displays a right-to-left override
character when downloading a file. In these cases, the name displayed in
the title bar differs from the name displayed in the dialog body. An
attacker could use this flaw to trick a user into downloading a file that
has a file name or extension that differs from what the user expected.
(CVE-2009-3376)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3374, CVE-2009-3380, CVE-2009-3382)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.15. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.15, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-27" />
        <updated date="2009-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1563.html">CVE-2009-1563</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3274.html">CVE-2009-3274</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3370.html">CVE-2009-3370</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3372.html">CVE-2009-3372</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3373.html">CVE-2009-3373</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3374.html">CVE-2009-3374</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3375.html">CVE-2009-3375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3376.html">CVE-2009-3376</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3380.html">CVE-2009-3380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3382.html">CVE-2009-3382</cve>
                <bugzilla href="http://bugzilla.redhat.com/524815" id="524815">CVE-2009-3274 Firefox: Predictable /tmp pathname use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530151" id="530151">CVE-2009-3370 Firefox form history vulnerable to stealing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530155" id="530155">CVE-2009-3372 Firefox crash in proxy auto-configuration regexp parsing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530156" id="530156">CVE-2009-3373 Firefox heap buffer overflow in GIF color map parser</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530157" id="530157">CVE-2009-3374 Firefox chrome privilege escalation in XPCVariant::VariantDataToJS()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530162" id="530162">CVE-2009-0689 (rejected CVE-2009-1563) Firefox heap buffer overflow in string to number conversion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530167" id="530167">CVE-2009-3375 Firefox cross-origin data theft through document.getSelection()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530168" id="530168">CVE-2009-3376 Firefox download filename spoofing with RTL override</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530567" id="530567">CVE-2009-3380 Firefox crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530569" id="530569">CVE-2009-3382 Firefox crashes with evidence of memory corruption</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530004" comment="nspr-devel is earlier than 0:4.7.6-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091186005" comment="nspr-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530002" comment="nspr is earlier than 0:4.7.6-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091186003" comment="nspr is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530008" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.15-3.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530006" comment="xulrunner is earlier than 0:1.9.0.15-3.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530010" comment="xulrunner-devel is earlier than 0:1.9.0.15-3.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530012" comment="firefox is earlier than 0:3.0.15-3.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530017" comment="nspr-devel is earlier than 0:4.7.6-1.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091184011" comment="nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530015" comment="nspr is earlier than 0:4.7.6-1.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091184009" comment="nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091530019" comment="firefox is earlier than 0:3.0.15-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091531" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1531: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1531-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1531.html" />
          <reference source="CVE" ref_id="CVE-2009-1563" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1563.html" />
          <reference source="CVE" ref_id="CVE-2009-3274" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3274.html" />
          <reference source="CVE" ref_id="CVE-2009-3375" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3375.html" />
          <reference source="CVE" ref_id="CVE-2009-3376" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3376.html" />
          <reference source="CVE" ref_id="CVE-2009-3380" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3380.html" />
          <reference source="CVE" ref_id="CVE-2009-3385" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3385.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A flaw was found in the way SeaMonkey creates temporary file names for
downloaded files. If a local attacker knows the name of a file SeaMonkey is
going to download, they can replace the contents of that file with
arbitrary contents. (CVE-2009-3274)

A heap-based buffer overflow flaw was found in the SeaMonkey string to
floating point conversion routines. A web page containing malicious
JavaScript could crash SeaMonkey or, potentially, execute arbitrary code
with the privileges of the user running SeaMonkey. (CVE-2009-1563)

A flaw was found in the way SeaMonkey handles text selection. A malicious
website may be able to read highlighted text in a different domain (e.g.
another website the user is viewing), bypassing the same-origin policy.
(CVE-2009-3375)

A flaw was found in the way SeaMonkey displays a right-to-left override
character when downloading a file. In these cases, the name displayed in
the title bar differs from the name displayed in the dialog body. An
attacker could use this flaw to trick a user into downloading a file that
has a file name or extension that differs from what the user expected.
(CVE-2009-3376)

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3380)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-27" />
        <updated date="2009-10-27" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1563.html">CVE-2009-1563</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3274.html">CVE-2009-3274</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3375.html">CVE-2009-3375</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3376.html">CVE-2009-3376</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3380.html">CVE-2009-3380</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3385.html">CVE-2009-3385</cve>
                <bugzilla href="http://bugzilla.redhat.com/524815" id="524815">CVE-2009-3274 Firefox: Predictable /tmp pathname use</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530162" id="530162">CVE-2009-0689 (rejected CVE-2009-1563) Firefox heap buffer overflow in string to number conversion</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530167" id="530167">CVE-2009-3375 Firefox cross-origin data theft through document.getSelection()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530168" id="530168">CVE-2009-3376 Firefox download filename spoofing with RTL override</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530567" id="530567">CVE-2009-3380 Firefox crashes with evidence of memory corruption</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531014" comment="seamonkey-nspr is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531020" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531016" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531018" comment="seamonkey-mail is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531002" comment="seamonkey is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531006" comment="seamonkey-devel is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531008" comment="seamonkey-chat is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531004" comment="seamonkey-nss is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531012" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.47.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531025" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-50.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531024" comment="seamonkey-mail is earlier than 0:1.0.9-50.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531023" comment="seamonkey is earlier than 0:1.0.9-50.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531028" comment="seamonkey-devel is earlier than 0:1.0.9-50.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531026" comment="seamonkey-chat is earlier than 0:1.0.9-50.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091531027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-50.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091535" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1535: pidgin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1535-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1535.html" />
          <reference source="CVE" ref_id="CVE-2009-2703" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2703.html" />
          <reference source="CVE" ref_id="CVE-2009-3083" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3083.html" />
          <reference source="CVE" ref_id="CVE-2009-3615" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3615.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

An invalid pointer dereference bug was found in the way the Pidgin OSCAR
protocol implementation processed lists of contacts. A remote attacker
could send a specially-crafted contact list to a user running Pidgin,
causing Pidgin to crash. (CVE-2009-3615)

A NULL pointer dereference flaw was found in the way the Pidgin IRC
protocol plug-in handles IRC topics. A malicious IRC server could send a
specially-crafted IRC TOPIC message, which once received by Pidgin, would
lead to a denial of service (Pidgin crash). (CVE-2009-2703)

A NULL pointer dereference flaw was found in the way the Pidgin MSN
protocol plug-in handles improper MSNSLP invitations. A remote attacker
could send a specially-crafted MSNSLP invitation request, which once
accepted by a valid Pidgin user, would lead to a denial of service (Pidgin
crash). (CVE-2009-3083)

All Pidgin users should upgrade to this updated package, which contains
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-29" />
        <updated date="2009-10-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2703.html">CVE-2009-2703</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3083.html">CVE-2009-3083</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3615.html">CVE-2009-3615</cve>
                <bugzilla href="http://bugzilla.redhat.com/521823" id="521823">CVE-2009-2703 Pidgin: NULL pointer dereference by handling IRC topic(s) (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521832" id="521832">CVE-2009-3083 Pidgin: NULL pointer dereference by processing incomplete MSN SLP invite (DoS)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529357" id="529357">CVE-2009-3615 Pidgin: Invalid pointer dereference (crash) after receiving contacts from SIM IM client</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091535002" comment="pidgin is earlier than 0:1.5.1-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091536" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1536: pidgin security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1536-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1536.html" />
          <reference source="CVE" ref_id="CVE-2009-3615" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3615.html" />
    
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously. The AOL
Open System for Communication in Realtime (OSCAR) protocol is used by the
AOL ICQ and AIM instant messaging systems.

An invalid pointer dereference bug was found in the way the Pidgin OSCAR
protocol implementation processed lists of contacts. A remote attacker
could send a specially-crafted contact list to a user running Pidgin,
causing Pidgin to crash. (CVE-2009-3615)

These packages upgrade Pidgin to version 2.6.3. Refer to the Pidgin release
notes for a full list of changes: http://developer.pidgin.im/wiki/ChangeLog

All Pidgin users should upgrade to these updated packages, which correct
this issue. Pidgin must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-10-29" />
        <updated date="2009-10-29" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3615.html">CVE-2009-3615</cve>
                <bugzilla href="http://bugzilla.redhat.com/529357" id="529357">CVE-2009-3615 Pidgin: Invalid pointer dereference (crash) after receiving contacts from SIM IM client</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536014" comment="finch is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060017" comment="finch is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536012" comment="libpurple is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060009" comment="libpurple is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536004" comment="libpurple-perl is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060011" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536002" comment="pidgin is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060003" comment="pidgin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536018" comment="finch-devel is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060007" comment="finch-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536016" comment="pidgin-devel is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536010" comment="pidgin-perl is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060013" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536008" comment="libpurple-devel is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060005" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536006" comment="libpurple-tcl is earlier than 0:2.6.3-2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060015" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536037" comment="finch is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060032" comment="finch is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536033" comment="libpurple is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060030" comment="libpurple is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536025" comment="libpurple-perl is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060038" comment="libpurple-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536021" comment="pidgin is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536035" comment="libpurple-devel is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060026" comment="libpurple-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536031" comment="finch-devel is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060034" comment="finch-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536027" comment="pidgin-devel is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060036" comment="pidgin-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536023" comment="pidgin-perl is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060028" comment="pidgin-perl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091536029" comment="libpurple-tcl is earlier than 0:2.6.3-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060024" comment="libpurple-tcl is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091541" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1541: kernel security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1541-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1541.html" />
          <reference source="CVE" ref_id="CVE-2009-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3547.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a NULL pointer dereference flaw was found in each of the following
functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and
pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could
be released by other processes before it is used to update the pipe's
reader and writer counters. This could lead to a local denial of service or
privilege escalation. (CVE-2009-3547, Important)

Users should upgrade to these updated packages, which contain a backported
patch to correct these issues. The system must be rebooted for this update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-03" />
        <updated date="2009-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3547.html">CVE-2009-3547</cve>
                <bugzilla href="http://bugzilla.redhat.com/530490" id="530490">CVE-2009-3547 kernel: fs: pipe.c null pointer dereference</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541002" comment="kernel is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541022" comment="kernel-doc is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541004" comment="kernel-devel is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541014" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541018" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541012" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541010" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541016" comment="kernel-xenU is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541008" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091541006" comment="kernel-smp is earlier than 0:2.6.9-89.0.16.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091548" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1548: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1548-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1548.html" />
          <reference source="CVE" ref_id="CVE-2009-2695" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2695.html" />
          <reference source="CVE" ref_id="CVE-2009-2908" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2908.html" />
          <reference source="CVE" ref_id="CVE-2009-3228" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3228.html" />
          <reference source="CVE" ref_id="CVE-2009-3286" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3286.html" />
          <reference source="CVE" ref_id="CVE-2009-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3547.html" />
          <reference source="CVE" ref_id="CVE-2009-3613" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3613.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a system with SELinux enforced was more permissive in allowing local
users in the unconfined_t domain to map low memory areas even if the
mmap_min_addr restriction was enabled. This could aid in the local
exploitation of NULL pointer dereference bugs. (CVE-2009-2695, Important)

* a NULL pointer dereference flaw was found in the eCryptfs implementation
in the Linux kernel. A local attacker could use this flaw to cause a local
denial of service or escalate their privileges. (CVE-2009-2908, Important)

* a flaw was found in the NFSv4 implementation. The kernel would do an
unnecessary permission check after creating a file. This check would
usually fail and leave the file with the permission bits set to random
values. Note: This is a server-side only issue. (CVE-2009-3286, Important)

* a NULL pointer dereference flaw was found in each of the following
functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and
pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could
be released by other processes before it is used to update the pipe's
reader and writer counters. This could lead to a local denial of service or
privilege escalation. (CVE-2009-3547, Important)

* a flaw was found in the Realtek r8169 Ethernet driver in the Linux
kernel. pci_unmap_single() presented a memory leak that could lead to IOMMU
space exhaustion and a system crash. An attacker on the local network could
abuse this flaw by using jumbo frames for large amounts of network traffic.
(CVE-2009-3613, Important)

* missing initialization flaws were found in the Linux kernel. Padding data
in several core network structures was not initialized properly before
being sent to user-space. These flaws could lead to information leaks.
(CVE-2009-3228, Moderate)

Bug fixes:

* with network bonding in the "balance-tlb" or "balance-alb" mode, the
primary setting for the primary slave device was lost when said device was
brought down. Bringing the slave back up did not restore the primary
setting. (BZ#517971)

* some faulty serial device hardware caused systems running the kernel-xen
kernel to take a very long time to boot. (BZ#524153)

* a caching bug in nfs_readdir() may have caused NFS clients to see
duplicate files or not see all files in a directory. (BZ#526960)

* the RHSA-2009:1243 update removed the mpt_msi_enable option, preventing
certain scripts from running. This update adds the option back. (BZ#526963)

* an iptables rule with the recent module and a hit count value greater
than the ip_pkt_list_tot parameter (the default is 20), did not have any
effect over packets, as the hit count could not be reached. (BZ#527434)

* a check has been added to the IPv4 code to make sure that rt is not NULL,
to help prevent future bugs in functions that call ip_append_data() from
being exploitable. (BZ#527436)

* a kernel panic occurred in certain conditions after reconfiguring a tape
drive's block size. (BZ#528133)

* when using the Linux Virtual Server (LVS) in a master and backup
configuration, and propagating active connections on the master to the
backup, the connection timeout value on the backup was hard-coded to 180
seconds, meaning connection information on the backup was soon lost. This
could prevent the successful failover of connections. The timeout value
can now be set via "ipvsadm --set". (BZ#528645)

* a bug in nfs4_do_open_expired() could have caused the reclaimer thread on
an NFSv4 client to enter an infinite loop. (BZ#529162)

* MSI interrupts may not have been delivered for r8169 based network cards
that have MSI interrupts enabled. This bug only affected certain systems.
(BZ#529366)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-03" />
        <updated date="2009-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2695.html">CVE-2009-2695</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2908.html">CVE-2009-2908</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3228.html">CVE-2009-3228</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3286.html">CVE-2009-3286</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3547.html">CVE-2009-3547</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3613.html">CVE-2009-3613</cve>
                <bugzilla href="http://bugzilla.redhat.com/517830" id="517830">CVE-2009-2695 kernel: SELinux and mmap_min_addr</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/517971" id="517971">A bond's preferred primary setting is lost after bringing down and up of the primary slave. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520990" id="520990">CVE-2009-3228 kernel: tc: uninitialised kernel memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524153" id="524153">dom0 freeze during kernel startup [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524520" id="524520">CVE-2009-3286 kernel: O_EXCL creates on NFSv4 are broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526960" id="526960">[NetApp 5.5 bug] nfs_readdir() may fail to return all the files in the directory [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526963" id="526963">[RFE] Re-enable "mpt_msi_enable" option in RHEL5 [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/527434" id="527434">kernel: ipt_recent: sanity check hit count [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/527436" id="527436">kernel: ipv4: make ip_append_data() handle NULL routing table [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/527534" id="527534">CVE-2009-2908 kernel ecryptfs NULL pointer dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528133" id="528133">kernel panics from list corruption when using a tape drive connected through cciss adapter [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528645" id="528645">LVS master and backup director - Synchronised connections on backup director have unsuitable timeout value [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529137" id="529137">CVE-2009-3613 kernel: flood ping cause out-of-iommu error and panic when mtu larger than 1500</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529162" id="529162">NFSv4 reclaimer thread in an infinite loop [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529366" id="529366">r8169 stopping all activity until the link is reset [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530490" id="530490">CVE-2009-3547 kernel: fs: pipe.c null pointer dereference</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548004" comment="kernel-headers is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548002" comment="kernel is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548024" comment="kernel-doc is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548020" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548012" comment="kernel-devel is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548008" comment="kernel-debug is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548018" comment="kernel-kdump is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548010" comment="kernel-xen-devel is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548006" comment="kernel-debug-devel is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548022" comment="kernel-PAE is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548016" comment="kernel-kdump-devel is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091548014" comment="kernel-xen is earlier than 0:2.6.18-164.6.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091549" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1549: wget security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1549-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1549.html" />
          <reference source="CVE" ref_id="CVE-2009-3490" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3490.html" />
    
    <description>GNU Wget is a file retrieval utility that can use HTTP, HTTPS, and FTP.

Daniel Stenberg reported that Wget is affected by the previously published
"null prefix attack", caused by incorrect handling of NULL characters in
X.509 certificates. If an attacker is able to get a carefully-crafted
certificate signed by a trusted Certificate Authority, the attacker could
use the certificate during a man-in-the-middle attack and potentially
confuse Wget into accepting it by mistake. (CVE-2009-3490)

Wget users should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-03" />
        <updated date="2009-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3490.html">CVE-2009-3490</cve>
                <bugzilla href="http://bugzilla.redhat.com/520454" id="520454">CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091549002" comment="wget is earlier than 0:1.11.4-2.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091549003" comment="wget is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091549005" comment="wget is earlier than 0:1.10.2-0.30E.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091549006" comment="wget is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091549008" comment="wget is earlier than 0:1.10.2-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091549006" comment="wget is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091550" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1550: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1550-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1550.html" />
          <reference source="CVE" ref_id="CVE-2008-5029" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5029.html" />
          <reference source="CVE" ref_id="CVE-2008-5300" ref_url="https://www.redhat.com/security/data/cve/CVE-2008-5300.html" />
          <reference source="CVE" ref_id="CVE-2009-1337" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1337.html" />
          <reference source="CVE" ref_id="CVE-2009-1385" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1385.html" />
          <reference source="CVE" ref_id="CVE-2009-1895" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1895.html" />
          <reference source="CVE" ref_id="CVE-2009-2848" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2848.html" />
          <reference source="CVE" ref_id="CVE-2009-3002" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3002.html" />
          <reference source="CVE" ref_id="CVE-2009-3547" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3547.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* when fput() was called to close a socket, the __scm_destroy() function in
the Linux kernel could make indirect recursive calls to itself. This could,
potentially, lead to a denial of service issue. (CVE-2008-5029, Important)

* the sendmsg() function in the Linux kernel did not block during UNIX
socket garbage collection. This could, potentially, lead to a local denial
of service. (CVE-2008-5300, Important)

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* a flaw was found in the Intel PRO/1000 network driver in the Linux
kernel. Frames with sizes near the MTU of an interface may be split across
multiple hardware receive descriptors. Receipt of such a frame could leak
through a validation check, leading to a corruption of the length check. A
remote attacker could use this flaw to send a specially-crafted packet that
would cause a denial of service or code execution. (CVE-2009-1385,
Important)

* the ADDR_COMPAT_LAYOUT and MMAP_PAGE_ZERO flags were not cleared when a
setuid or setgid program was executed. A local, unprivileged user could use
this flaw to bypass the mmap_min_addr protection mechanism and perform a
NULL pointer dereference attack, or bypass the Address Space Layout
Randomization (ASLR) security feature. (CVE-2009-1895, Important)

* it was discovered that, when executing a new process, the clear_child_tid
pointer in the Linux kernel is not cleared. If this pointer points to a
writable portion of the memory of the new program, the kernel could corrupt
four bytes of memory, possibly leading to a local denial of service or
privilege escalation. (CVE-2009-2848, Important)

* missing initialization flaws were found in getname() implementations in
the IrDA sockets, AppleTalk DDP protocol, NET/ROM protocol, and ROSE
protocol implementations in the Linux kernel. Certain data structures in
these getname() implementations were not initialized properly before being
copied to user-space. These flaws could lead to an information leak.
(CVE-2009-3002, Important)

* a NULL pointer dereference flaw was found in each of the following
functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and
pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could
be released by other processes before it is used to update the pipe's
reader and writer counters. This could lead to a local denial of service or
privilege escalation. (CVE-2009-3547, Important)

Bug fixes:

* this update adds the mmap_min_addr tunable and restriction checks to help
prevent unprivileged users from creating new memory mappings below the
minimum address. This can help prevent the exploitation of NULL pointer
dereference bugs. Note that mmap_min_addr is set to zero (disabled) by
default for backwards compatibility. (BZ#512642)

* a bridge reference count problem in IPv6 has been fixed. (BZ#457010)

* enforce null-termination of user-supplied arguments to setsockopt().
(BZ#505514)

* the gcc flag "-fno-delete-null-pointer-checks" was added to the kernel
build options. This prevents gcc from optimizing out NULL pointer checks
after the first use of a pointer. NULL pointer bugs are often exploited by
attackers. Keeping these checks is a safety measure. (BZ#511185)

* a check has been added to the IPv4 code to make sure that rt is not NULL,
to help prevent future bugs in functions that call ip_append_data() from
being exploitable. (BZ#520300)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-03" />
        <updated date="2009-11-03" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5029.html">CVE-2008-5029</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2008-5300.html">CVE-2008-5300</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1337.html">CVE-2009-1337</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1385.html">CVE-2009-1385</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1895.html">CVE-2009-1895</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2848.html">CVE-2009-2848</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3002.html">CVE-2009-3002</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3547.html">CVE-2009-3547</cve>
                <bugzilla href="http://bugzilla.redhat.com/457010" id="457010">ipv6: use timer pending to fix bridge reference count problem [rhel-3.9]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470201" id="470201">CVE-2008-5029 kernel: Unix sockets kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473259" id="473259">CVE-2008-5300 kernel: fix soft lockups/OOM issues with unix socket garbage collector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493771" id="493771">CVE-2009-1337 kernel: exit_notify: kill the wrong capable(CAP_KILL) check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/502981" id="502981">CVE-2009-1385 kernel: e1000_clean_rx_irq() denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/505514" id="505514">kernel: ensure devname passed to SO_BINDTODEVICE is NULL-terminated [rhel-3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511171" id="511171">CVE-2009-1895 kernel: personality: fix PER_CLEAR_ON_SETID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/511185" id="511185">kernel: build with -fno-delete-null-pointer-checks [rhel-3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512642" id="512642">kernel: security: implement mmap_min_addr infrastructure [rhel-3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515423" id="515423">CVE-2009-2848 kernel: execve: must clear current->clear_child_tid</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/519305" id="519305">CVE-2009-3001, CVE-2009-3002 kernel: numerous getname() infoleaks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/520300" id="520300">kernel: ipv4: make ip_append_data() handle NULL routing table [rhel-3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530490" id="530490">CVE-2009-3547 kernel: fs: pipe.c null pointer dereference</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550006" comment="kernel-source is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233007" comment="kernel-source is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550002" comment="kernel is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550010" comment="kernel-doc is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550016" comment="kernel-hugemem-unsupported is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233019" comment="kernel-hugemem-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550018" comment="kernel-hugemem is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550014" comment="kernel-BOOT is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233015" comment="kernel-BOOT is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550012" comment="kernel-smp-unsupported is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233005" comment="kernel-smp-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550004" comment="kernel-unsupported is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091233011" comment="kernel-unsupported is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091550008" comment="kernel-smp is earlier than 0:2.4.21-63.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091560" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1560: java-1.6.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1560-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1560.html" />
          <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html" />
          <reference source="CVE" ref_id="CVE-2009-3728" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3728.html" />
          <reference source="CVE" ref_id="CVE-2009-3729" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3729.html" />
          <reference source="CVE" ref_id="CVE-2009-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3865.html" />
          <reference source="CVE" ref_id="CVE-2009-3866" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3866.html" />
          <reference source="CVE" ref_id="CVE-2009-3867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3867.html" />
          <reference source="CVE" ref_id="CVE-2009-3868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3868.html" />
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html" />
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html" />
          <reference source="CVE" ref_id="CVE-2009-3872" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3872.html" />
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html" />
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html" />
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html" />
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html" />
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html" />
          <reference source="CVE" ref_id="CVE-2009-3879" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3879.html" />
          <reference source="CVE" ref_id="CVE-2009-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3880.html" />
          <reference source="CVE" ref_id="CVE-2009-3881" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3881.html" />
          <reference source="CVE" ref_id="CVE-2009-3882" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3882.html" />
          <reference source="CVE" ref_id="CVE-2009-3883" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3883.html" />
          <reference source="CVE" ref_id="CVE-2009-3884" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3884.html" />
          <reference source="CVE" ref_id="CVE-2009-3886" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3886.html" />
    
    <description>The Sun 1.6.0 Java release includes the Sun Java 6 Runtime Environment and
the Sun Java 6 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 6 Runtime
Environment and the Sun Java 6 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2009-2409, CVE-2009-3728, CVE-2009-3729, CVE-2009-3865,
CVE-2009-3866, CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871,
CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876,
CVE-2009-3877, CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882,
CVE-2009-3883, CVE-2009-3884, CVE-2009-3886)

Users of java-1.6.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-09" />
        <updated date="2009-11-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2409.html">CVE-2009-2409</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3728.html">CVE-2009-3728</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3729.html">CVE-2009-3729</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3865.html">CVE-2009-3865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3866.html">CVE-2009-3866</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3867.html">CVE-2009-3867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3868.html">CVE-2009-3868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3872.html">CVE-2009-3872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3879.html">CVE-2009-3879</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3880.html">CVE-2009-3880</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3881.html">CVE-2009-3881</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3882.html">CVE-2009-3882</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3883.html">CVE-2009-3883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3884.html">CVE-2009-3884</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3886.html">CVE-2009-3886</cve>
                <bugzilla href="http://bugzilla.redhat.com/510197" id="510197">CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530057" id="530057">CVE-2009-3875 OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530062" id="530062">CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530063" id="530063">CVE-2009-3871 OpenJDK JRE AWT setBytePixels heap overflow (6872358)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530067" id="530067">CVE-2009-3874 OpenJDK ImageI/O JPEG heap overflow  (6874643)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530098" id="530098">CVE-2009-3728 OpenJDK ICC_Profile file existence detection information leak (6631533)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530173" id="530173">CVE-2009-3881 OpenJDK resurrected classloaders can still have children (6636650)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530175" id="530175">CVE-2009-3882 CVE-2009-3883 OpenJDK information leaks in mutable variables (6657026,6657138)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530296" id="530296">CVE-2009-3880 OpenJDK UI logging information leakage(6664512)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530297" id="530297">CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530300" id="530300">CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532904" id="532904">CVE-2009-3729 JRE TrueType font parsing crash (6815780)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532906" id="532906">CVE-2009-3872 JRE JPEG JFIF Decoder issue (6862969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532914" id="532914">CVE-2009-3886 JRE REGRESSION:have problem to run JNLP app and applets with signed Jar files (6870531)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533211" id="533211">CVE-2009-3865 java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533212" id="533212">CVE-2009-3866 java-1.6.0-sun: Privilege escalation in the Java Web Start Installer  (6872824)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533214" id="533214">CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533215" id="533215">CVE-2009-3868 java-1.5.0-sun, java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091560010" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392007" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091560002" comment="java-1.6.0-sun is earlier than 1:1.6.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392003" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091560008" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392011" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091560006" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392013" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091560004" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392005" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091560012" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.17-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090392009" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091561" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1561: libvorbis security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1561-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1561.html" />
          <reference source="CVE" ref_id="CVE-2009-3379" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3379.html" />
    
    <description>The libvorbis packages contain runtime libraries for use in programs that
support Ogg Vorbis. Ogg Vorbis is a fully open, non-proprietary, patent-and
royalty-free, general-purpose compressed audio format.

Multiple flaws were found in the libvorbis library. A specially-crafted Ogg
Vorbis media format file (Ogg) could cause an application using libvorbis
to crash or, possibly, execute arbitrary code when opened. (CVE-2009-3379)

Users of libvorbis should upgrade to these updated packages, which contain
backported patches to correct these issues. The desktop must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-09" />
        <updated date="2009-11-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3379.html">CVE-2009-3379</cve>
                <bugzilla href="http://bugzilla.redhat.com/531765" id="531765">CVE-2009-3379 libvorbis: security fixes mentioned in MFSA 2009-63</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091561004" comment="libvorbis-devel is earlier than 1:1.1.2-3.el5_4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219005" comment="libvorbis-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091561002" comment="libvorbis is earlier than 1:1.1.2-3.el5_4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219003" comment="libvorbis is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091561009" comment="libvorbis-devel is earlier than 1:1.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091561007" comment="libvorbis is earlier than 1:1.0-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091561013" comment="libvorbis-devel is earlier than 1:1.1.0-3.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219010" comment="libvorbis-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091561012" comment="libvorbis is earlier than 1:1.1.0-3.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091219008" comment="libvorbis is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091571" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1571: java-1.5.0-sun security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1571-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1571.html" />
          <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html" />
          <reference source="CVE" ref_id="CVE-2009-3728" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3728.html" />
          <reference source="CVE" ref_id="CVE-2009-3867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3867.html" />
          <reference source="CVE" ref_id="CVE-2009-3868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3868.html" />
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html" />
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html" />
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html" />
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html" />
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html" />
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html" />
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html" />
          <reference source="CVE" ref_id="CVE-2009-3879" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3879.html" />
          <reference source="CVE" ref_id="CVE-2009-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3880.html" />
          <reference source="CVE" ref_id="CVE-2009-3881" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3881.html" />
          <reference source="CVE" ref_id="CVE-2009-3882" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3882.html" />
          <reference source="CVE" ref_id="CVE-2009-3883" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3883.html" />
          <reference source="CVE" ref_id="CVE-2009-3884" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3884.html" />
    
    <description>The Sun 1.5.0 Java release includes the Sun Java 5 Runtime Environment and
the Sun Java 5 Software Development Kit.

This update fixes several vulnerabilities in the Sun Java 5 Runtime
Environment and the Sun Java 5 Software Development Kit. These
vulnerabilities are summarized on the "Advance notification of Security
Updates for Java SE" page from Sun Microsystems, listed in the References
section. (CVE-2009-2409, CVE-2009-3728, CVE-2009-3873, CVE-2009-3876,
CVE-2009-3877, CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882,
CVE-2009-3883, CVE-2009-3884)

Note: This is the final update for the java-1.5.0-sun packages, as the Sun
Java SE Release family 5.0 has now reached End of Service Life. The next
update will remove the java-1.5.0-sun packages.

An alternative to Sun Java SE 5.0 is the Java 2 Technology Edition of the
IBM Developer Kit for Linux, which is available from the Extras and
Supplementary channels on the Red Hat Network. For users of applications
that are capable of using the Java 6 runtime, the OpenJDK open source JDK
is included in Red Hat Enterprise Linux 5 (since 5.3) and is supported by
Red Hat.

Users of java-1.5.0-sun should upgrade to these updated packages, which
correct these issues. All running instances of Sun Java must be restarted
for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-10" />
        <updated date="2009-11-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2409.html">CVE-2009-2409</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3728.html">CVE-2009-3728</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3867.html">CVE-2009-3867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3868.html">CVE-2009-3868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3879.html">CVE-2009-3879</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3880.html">CVE-2009-3880</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3881.html">CVE-2009-3881</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3882.html">CVE-2009-3882</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3883.html">CVE-2009-3883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3884.html">CVE-2009-3884</cve>
                <bugzilla href="http://bugzilla.redhat.com/510197" id="510197">CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530098" id="530098">CVE-2009-3728 OpenJDK ICC_Profile file existence detection information leak (6631533)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530173" id="530173">CVE-2009-3881 OpenJDK resurrected classloaders can still have children (6636650)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530175" id="530175">CVE-2009-3882 CVE-2009-3883 OpenJDK information leaks in mutable variables (6657026,6657138)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530296" id="530296">CVE-2009-3880 OpenJDK UI logging information leakage(6664512)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530297" id="530297">CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530300" id="530300">CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091571012" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.22-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394013" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091571002" comment="java-1.5.0-sun is earlier than 0:1.5.0.22-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394003" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091571006" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.22-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394009" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091571008" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.22-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394007" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091571010" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.22-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394005" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091571004" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.22-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090394011" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091572" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1572: 4Suite security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1572-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1572.html" />
          <reference source="CVE" ref_id="CVE-2009-3720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3720.html" />
    
    <description>The 4Suite package contains XML-related tools and libraries for Python,
including 4DOM, 4XSLT, 4XPath, 4RDF, and 4XPointer.

A buffer over-read flaw was found in the way 4Suite's XML parser handles
malformed UTF-8 sequences when processing XML files. A specially-crafted
XML file could cause applications using the 4Suite library to crash while
parsing the file. (CVE-2009-3720)

Note: In Red Hat Enterprise Linux 3, this flaw only affects a non-default
configuration of the 4Suite package: configurations where the beta version
of the cDomlette module is enabled.

All 4Suite users should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing the updated
package, applications using the 4Suite XML-related tools and libraries must
be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-10" />
        <updated date="2009-11-10" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3720.html">CVE-2009-3720</cve>
                <bugzilla href="http://bugzilla.redhat.com/531697" id="531697">CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091572002" comment="4Suite is earlier than 0:0.11.1-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091572003" comment="4Suite is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091572005" comment="4Suite is earlier than 0:1.0-3.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091572003" comment="4Suite is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091579" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1579: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1579-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1579.html" />
          <reference source="CVE" ref_id="CVE-2009-3094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3094.html" />
          <reference source="CVE" ref_id="CVE-2009-3095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3095.html" />
          <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update partially mitigates this flaw for SSL
sessions to HTTP servers using mod_ssl by rejecting client-requested
renegotiation. (CVE-2009-3555)

Note: This update does not fully resolve the issue for HTTPS servers. An
attack is still possible in configurations that require a server-initiated
renegotiation. Refer to the following Knowledgebase article for further
information: http://kbase.redhat.com/faq/docs/DOC-20491

A NULL pointer dereference flaw was found in the Apache mod_proxy_ftp
module. A malicious FTP server to which requests are being proxied could
use this flaw to crash an httpd child process via a malformed reply to the
EPSV or PASV commands, resulting in a limited denial of service.
(CVE-2009-3094)

A second flaw was found in the Apache mod_proxy_ftp module. In a reverse
proxy configuration, a remote attacker could use this flaw to bypass
intended access restrictions by creating a carefully-crafted HTTP
Authorization header, allowing the attacker to send arbitrary commands to
the FTP server. (CVE-2009-3095)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-11" />
        <updated date="2009-11-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3094.html">CVE-2009-3094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3095.html">CVE-2009-3095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3555.html">CVE-2009-3555</cve>
                <bugzilla href="http://bugzilla.redhat.com/521619" id="521619">CVE-2009-3094 httpd: NULL pointer defer in mod_proxy_ftp caused by crafted EPSV and PASV reply</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/522209" id="522209">CVE-2009-3095 httpd: mod_proxy_ftp FTP command injection via Authorization HTTP header</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533125" id="533125">CVE-2009-3555 TLS: MITM attacks via session renegotiation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579006" comment="httpd-manual is earlier than 0:2.2.3-31.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075005" comment="httpd-manual is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579008" comment="httpd-devel is earlier than 0:2.2.3-31.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075007" comment="httpd-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579004" comment="mod_ssl is earlier than 0:2.2.3-31.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075009" comment="mod_ssl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579002" comment="httpd is earlier than 0:2.2.3-31.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075003" comment="httpd is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579015" comment="httpd-devel is earlier than 0:2.0.46-77.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579013" comment="mod_ssl is earlier than 0:2.0.46-77.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091579011" comment="httpd is earlier than 0:2.0.46-77.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091580" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1580: httpd security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1580-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1580.html" />
          <reference source="CVE" ref_id="CVE-2009-1891" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1891.html" />
          <reference source="CVE" ref_id="CVE-2009-3094" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3094.html" />
          <reference source="CVE" ref_id="CVE-2009-3095" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3095.html" />
          <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html" />
    
    <description>The Apache HTTP Server is a popular Web server.

A flaw was found in the way the TLS/SSL (Transport Layer Security/Secure
Sockets Layer) protocols handle session renegotiation. A man-in-the-middle
attacker could use this flaw to prefix arbitrary plain text to a client's
session (for example, an HTTPS connection to a website). This could force
the server to process an attacker's request as if authenticated using the
victim's credentials. This update partially mitigates this flaw for SSL
sessions to HTTP servers using mod_ssl by rejecting client-requested
renegotiation. (CVE-2009-3555)

Note: This update does not fully resolve the issue for HTTPS servers. An
attack is still possible in configurations that require a server-initiated
renegotiation. Refer to the following Knowledgebase article for further
information: http://kbase.redhat.com/faq/docs/DOC-20491

A denial of service flaw was found in the Apache mod_deflate module. This
module continued to compress large files until compression was complete,
even if the network connection that requested the content was closed before
compression completed. This would cause mod_deflate to consume large
amounts of CPU if mod_deflate was enabled for a large file. (CVE-2009-1891)

A NULL pointer dereference flaw was found in the Apache mod_proxy_ftp
module. A malicious FTP server to which requests are being proxied could
use this flaw to crash an httpd child process via a malformed reply to the
EPSV or PASV commands, resulting in a limited denial of service.
(CVE-2009-3094)

A second flaw was found in the Apache mod_proxy_ftp module. In a reverse
proxy configuration, a remote attacker could use this flaw to bypass
intended access restrictions by creating a carefully-crafted HTTP
Authorization header, allowing the attacker to send arbitrary commands to
the FTP server. (CVE-2009-3095)

All httpd users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, the httpd daemon must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-11" />
        <updated date="2009-11-11" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1891.html">CVE-2009-1891</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3094.html">CVE-2009-3094</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3095.html">CVE-2009-3095</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3555.html">CVE-2009-3555</cve>
                <bugzilla href="http://bugzilla.redhat.com/509125" id="509125">CVE-2009-1891 httpd: possible temporary DoS (CPU consumption) in mod_deflate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/521619" id="521619">CVE-2009-3094 httpd: NULL pointer defer in mod_proxy_ftp caused by crafted EPSV and PASV reply</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/522209" id="522209">CVE-2009-3095 httpd: mod_proxy_ftp FTP command injection via Authorization HTTP header</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533125" id="533125">CVE-2009-3555 TLS: MITM attacks via session renegotiation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091580006" comment="httpd-manual is earlier than 0:2.0.52-41.ent.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091580007" comment="httpd-manual is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091580010" comment="httpd-suexec is earlier than 0:2.0.52-41.ent.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091580011" comment="httpd-suexec is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091580008" comment="httpd-devel is earlier than 0:2.0.52-41.ent.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108005" comment="httpd-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091580004" comment="mod_ssl is earlier than 0:2.0.52-41.ent.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108007" comment="mod_ssl is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091580002" comment="httpd is earlier than 0:2.0.52-41.ent.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091108003" comment="httpd is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091582" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1582: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1582-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1582.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
          <reference source="CVE" ref_id="CVE-2009-2670" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2670.html" />
          <reference source="CVE" ref_id="CVE-2009-2671" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2671.html" />
          <reference source="CVE" ref_id="CVE-2009-2672" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2672.html" />
          <reference source="CVE" ref_id="CVE-2009-2673" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2673.html" />
          <reference source="CVE" ref_id="CVE-2009-2674" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2674.html" />
          <reference source="CVE" ref_id="CVE-2009-2675" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2675.html" />
          <reference source="CVE" ref_id="CVE-2009-2676" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2676.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-2625, CVE-2009-2670, CVE-2009-2671,
CVE-2009-2672, CVE-2009-2673, CVE-2009-2674, CVE-2009-2675, CVE-2009-2676)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR6 Java release. All running instances
of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-12" />
        <updated date="2009-11-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2670.html">CVE-2009-2670</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2671.html">CVE-2009-2671</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2672.html">CVE-2009-2672</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2673.html">CVE-2009-2673</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2674.html">CVE-2009-2674</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2675.html">CVE-2009-2675</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2676.html">CVE-2009-2676</cve>
                <bugzilla href="http://bugzilla.redhat.com/512896" id="512896">CVE-2009-2670 OpenJDK Untrusted applet System properties access (6738524)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512907" id="512907">CVE-2009-2671 CVE-2009-2672 OpenJDK Proxy mechanism information leaks  (6801071)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512914" id="512914">CVE-2009-2673 OpenJDK proxy mechanism allows non-authorized socket connections  (6801497)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512915" id="512915">CVE-2009-2674 Java Web Start Buffer JPEG processing integer overflow (6823373)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512920" id="512920">CVE-2009-2675 Java Web Start Buffer unpack200 processing integer overflow (6830335)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/515890" id="515890">CVE-2009-2676 JRE applet launcher vulnerability</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582014" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015011" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582006" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582004" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015007" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582016" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015017" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582012" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015005" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582010" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015013" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091582008" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.6-1jpp.3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015015" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091584" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1584: java-1.6.0-openjdk security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1584-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1584.html" />
          <reference source="CVE" ref_id="CVE-2009-2409" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2409.html" />
          <reference source="CVE" ref_id="CVE-2009-3728" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3728.html" />
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html" />
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html" />
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html" />
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html" />
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html" />
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html" />
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html" />
          <reference source="CVE" ref_id="CVE-2009-3879" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3879.html" />
          <reference source="CVE" ref_id="CVE-2009-3880" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3880.html" />
          <reference source="CVE" ref_id="CVE-2009-3881" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3881.html" />
          <reference source="CVE" ref_id="CVE-2009-3882" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3882.html" />
          <reference source="CVE" ref_id="CVE-2009-3883" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3883.html" />
          <reference source="CVE" ref_id="CVE-2009-3884" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3884.html" />
    
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

An integer overflow flaw and buffer overflow flaws were found in the way
the JRE processed image files. An untrusted applet or application could use
these flaws to extend its privileges, allowing it to read and write local
files, as well as to execute local applications with the privileges of the
user running the applet or application. (CVE-2009-3869, CVE-2009-3871,
CVE-2009-3873, CVE-2009-3874)

An information leak was found in the JRE. An untrusted applet or
application could use this flaw to extend its privileges, allowing it to
read and write local files, as well as to execute local applications with
the privileges of the user running the applet or application. (CVE-2009-3881)

It was discovered that the JRE still accepts certificates with MD2 hash
signatures, even though MD2 is no longer considered a cryptographically
strong algorithm. This could make it easier for an attacker to create a
malicious certificate that would be treated as trusted by the JRE. With
this update, the JRE disables the use of the MD2 algorithm inside
signatures by default. (CVE-2009-2409)

A timing attack flaw was found in the way the JRE processed HMAC digests.
This flaw could aid an attacker using forged digital signatures to bypass
authentication checks. (CVE-2009-3875)

Two denial of service flaws were found in the JRE. These could be exploited
in server-side application scenarios that process DER-encoded
(Distinguished Encoding Rules) data. (CVE-2009-3876, CVE-2009-3877)

An information leak was found in the way the JRE handled color profiles. An
attacker could use this flaw to discover the existence of files outside of
the color profiles directory. (CVE-2009-3728)

A flaw in the JRE with passing arrays to the X11GraphicsDevice API was
found. An untrusted applet or application could use this flaw to access and
modify the list of supported graphics configurations. This flaw could also
lead to sensitive information being leaked to unprivileged code.
(CVE-2009-3879)

It was discovered that the JRE passed entire objects to the logging API.
This could lead to sensitive information being leaked to either untrusted
or lower-privileged code from an attacker-controlled applet which has
access to the logging API and is therefore able to manipulate (read and/or
call) the passed objects. (CVE-2009-3880)

Potential information leaks were found in various mutable static variables.
These could be exploited in application scenarios that execute untrusted
scripting code. (CVE-2009-3882, CVE-2009-3883)

An information leak was found in the way the TimeZone.getTimeZone method
was handled. This method could load time zone files that are outside of the
[JRE_HOME]/lib/zi/ directory, allowing a remote attacker to probe the local
file system. (CVE-2009-3884)

Note: The flaws concerning applets in this advisory, CVE-2009-3869,
CVE-2009-3871, CVE-2009-3873, CVE-2009-3874, CVE-2009-3879, CVE-2009-3880,
CVE-2009-3881 and CVE-2009-3884, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-16" />
        <updated date="2009-11-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2409.html">CVE-2009-2409</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3728.html">CVE-2009-3728</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3879.html">CVE-2009-3879</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3880.html">CVE-2009-3880</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3881.html">CVE-2009-3881</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3882.html">CVE-2009-3882</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3883.html">CVE-2009-3883</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3884.html">CVE-2009-3884</cve>
                <bugzilla href="http://bugzilla.redhat.com/510197" id="510197">CVE-2009-2409 deprecate MD2 in SSL cert validation (Kaminsky)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530057" id="530057">CVE-2009-3875 OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530062" id="530062">CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530063" id="530063">CVE-2009-3871 OpenJDK JRE AWT setBytePixels heap overflow (6872358)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530067" id="530067">CVE-2009-3874 OpenJDK ImageI/O JPEG heap overflow  (6874643)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530098" id="530098">CVE-2009-3728 OpenJDK ICC_Profile file existence detection information leak (6631533)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530173" id="530173">CVE-2009-3881 OpenJDK resurrected classloaders can still have children (6636650)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530175" id="530175">CVE-2009-3882 CVE-2009-3883 OpenJDK information leaks in mutable variables (6657026,6657138)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530296" id="530296">CVE-2009-3880 OpenJDK UI logging information leakage(6664512)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530297" id="530297">CVE-2009-3879 OpenJDK GraphicsConfiguration information leak(6822057)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530300" id="530300">CVE-2009-3884 OpenJDK zoneinfo file existence information leak (6824265)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091584002" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-1.7.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377003" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091584010" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-1.7.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377009" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091584004" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-1.7.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377011" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091584006" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-1.7.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377005" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091584008" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-1.7.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377007" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091585" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1585: samba3x security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1585-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1585.html" />
          <reference source="CVE" ref_id="CVE-2009-1888" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-1888.html" />
          <reference source="CVE" ref_id="CVE-2009-2813" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2813.html" />
          <reference source="CVE" ref_id="CVE-2009-2906" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2906.html" />
          <reference source="CVE" ref_id="CVE-2009-2948" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2948.html" />
    
    <description>Samba is a suite of programs used by machines to share files, printers, and
other information. These samba3x packages provide Samba 3.3, which is a
Technology Preview for Red Hat Enterprise Linux 5. These packages cannot be
installed in parallel with the samba packages. Note: Technology Previews
are not intended for production use.

A denial of service flaw was found in the Samba smbd daemon. An
authenticated, remote user could send a specially-crafted response that
would cause an smbd child process to enter an infinite loop. An
authenticated, remote user could use this flaw to exhaust system resources
by opening multiple CIFS sessions. (CVE-2009-2906)

An uninitialized data access flaw was discovered in the smbd daemon when
using the non-default "dos filemode" configuration option in "smb.conf". An
authenticated, remote user with write access to a file could possibly use
this flaw to change an access control list for that file, even when such
access should have been denied. (CVE-2009-1888)

A flaw was discovered in the way Samba handled users without a home
directory set in the back-end password database (e.g. "/etc/passwd"). If a
share for the home directory of such a user was created (e.g. using the
automated "[homes]" share), any user able to access that share could see
the whole file system, possibly bypassing intended access restrictions.
(CVE-2009-2813)

The mount.cifs program printed CIFS passwords as part of its debug output
when running in verbose mode. When mount.cifs had the setuid bit set, a
local, unprivileged user could use this flaw to disclose passwords from a
file that would otherwise be inaccessible to that user. Note: mount.cifs
from the samba3x packages distributed by Red Hat does not have the setuid
bit set. This flaw only affected systems where the setuid bit was manually
set by an administrator. (CVE-2009-2948)

This update also fixes the following bugs:

* the samba3x packages contained missing and conflicting license
information. License information was missing for the libtalloc, libtdb, and
tdb-tools packages. The samba3x-common package provided a COPYING file;
however, it stated the license was GPLv2, while RPM metadata stated the
licenses were either GPLv3 or LGPLv3. This update adds the correct
licensing information to the samba3x-common, libsmbclient, libtalloc,
libtdb, and tdb-tools packages. (BZ#528633)

* the upstream Samba version in the samba3x packages distributed with the
RHEA-2009:1399 update contained broken implementations of the Netlogon
credential chain and SAMR access checks security subsystems. This prevented
Samba from acting as a domain controller: Client systems could not join the
domain; users could not authenticate; and systems could not access the user
and group list. (BZ#524551)

* this update resolves interoperability issues with Windows 7 and Windows
Server 2008 R2. (BZ#529022)

These packages upgrade Samba from version 3.3.5 to version 3.3.8. Refer to
the Samba Release Notes for a list of changes between versions:
http://samba.org/samba/history/

Users of samba3x should upgrade to these updated packages, which resolve
these issues. After installing this update, the smb service will be
restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-16" />
        <updated date="2009-11-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-1888.html">CVE-2009-1888</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2813.html">CVE-2009-2813</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2906.html">CVE-2009-2906</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2948.html">CVE-2009-2948</cve>
                <bugzilla href="http://bugzilla.redhat.com/506996" id="506996">CVE-2009-1888 Samba improper file access</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/523752" id="523752">CVE-2009-2813 Samba: Share restriction bypass via home-less directory user account(s)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/524551" id="524551">samba3x 3.3.4 is broken as domain controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526074" id="526074">CVE-2009-2948 samba: information disclosure in suid mount.cifs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/526645" id="526645">CVE-2009-2906 samba: infinite loop flaw in smbd on unexpected oplock break notification reply</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/528633" id="528633">License problem for Samba3X in x86_64 supplementary image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529022" id="529022">Interoperation with Windows 7 and Windows 2008 (R2) broken</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585016" comment="tdb-tools is earlier than 0:1.1.2-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585017" comment="tdb-tools is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585008" comment="samba3x-swat is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585009" comment="samba3x-swat is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585030" comment="libtdb is earlier than 0:1.1.2-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585031" comment="libtdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585028" comment="samba3x-doc is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585029" comment="samba3x-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585024" comment="samba3x-client is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585025" comment="samba3x-client is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585014" comment="libsmbclient is earlier than 0:3.0.34-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585015" comment="libsmbclient is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585004" comment="libtalloc-devel is earlier than 0:1.2.0-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585005" comment="libtalloc-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585006" comment="samba3x-winbind is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585007" comment="samba3x-winbind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585012" comment="libsmbclient-devel is earlier than 0:3.0.34-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585013" comment="libsmbclient-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585002" comment="samba3x is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585003" comment="samba3x is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585018" comment="samba3x-winbind-devel is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585019" comment="samba3x-winbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585026" comment="samba3x-domainjoin-gui is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585027" comment="samba3x-domainjoin-gui is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585022" comment="samba3x-common is earlier than 0:3.3.8-0.46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585023" comment="samba3x-common is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585020" comment="libtdb-devel is earlier than 0:1.1.2-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585021" comment="libtdb-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091585010" comment="libtalloc is earlier than 0:1.2.0-46.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091585011" comment="libtalloc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091595" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1595: cups security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1595-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1595.html" />
          <reference source="CVE" ref_id="CVE-2009-2820" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2820.html" />
          <reference source="CVE" ref_id="CVE-2009-3553" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3553.html" />
    
    <description>The Common UNIX Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

A use-after-free flaw was found in the way CUPS handled references in its
file descriptors-handling interface. A remote attacker could, in a
specially-crafted way, query for the list of current print jobs for a
specific printer, leading to a denial of service (cupsd crash).
(CVE-2009-3553)

Several cross-site scripting (XSS) flaws were found in the way the CUPS web
server interface processed HTML form content. If a remote attacker could
trick a local user who is logged into the CUPS web interface into visiting
a specially-crafted HTML page, the attacker could retrieve and potentially
modify confidential CUPS administration data. (CVE-2009-2820)

Red Hat would like to thank Aaron Sigel of Apple Product Security for
responsibly reporting the CVE-2009-2820 issue.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2010 Red Hat, Inc.</rights>
        <issued date="2009-11-18" />
        <updated date="2010-01-12" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2820.html">CVE-2009-2820</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3553.html">CVE-2009-3553</cve>
                <bugzilla href="http://bugzilla.redhat.com/529833" id="529833">CVE-2009-2820 cups: Several XSS flaws in forms processed by CUPS web interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530111" id="530111">CVE-2009-3553 cups: Use-after-free (crash) due improper reference counting in abstract file descriptors handling interface</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091595006" comment="cups-lpd is earlier than 1:1.3.7-11.el5_4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091595008" comment="cups-devel is earlier than 1:1.3.7-11.el5_4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429005" comment="cups-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091595004" comment="cups-libs is earlier than 1:1.3.7-11.el5_4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429009" comment="cups-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091595002" comment="cups is earlier than 1:1.3.7-11.el5_4.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429003" comment="cups is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091601" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1601: kdelibs security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1601-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1601.html" />
          <reference source="CVE" ref_id="CVE-2009-0689" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0689.html" />
    
    <description>The kdelibs packages provide libraries for the K Desktop Environment (KDE).

A buffer overflow flaw was found in the kdelibs string to floating point
conversion routines. A web page containing malicious JavaScript could crash
Konqueror or, potentially, execute arbitrary code with the privileges of
the user running Konqueror. (CVE-2009-0689)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. The desktop must be restarted (log out, then
log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-24" />
        <updated date="2009-11-24" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0689.html">CVE-2009-0689</cve>
                <bugzilla href="http://bugzilla.redhat.com/539784" id="539784">CVE-2009-0689 kdelibs remote array overrun</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091601004" comment="kdelibs-apidocs is earlier than 6:3.5.4-25.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127005" comment="kdelibs-apidocs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091601002" comment="kdelibs is earlier than 6:3.5.4-25.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127003" comment="kdelibs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091601006" comment="kdelibs-devel is earlier than 6:3.5.4-25.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127007" comment="kdelibs-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091601009" comment="kdelibs is earlier than 6:3.3.1-17.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127010" comment="kdelibs is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091601011" comment="kdelibs-devel is earlier than 6:3.3.1-17.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091127012" comment="kdelibs-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091615" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1615: xerces-j2 security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1615-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1615.html" />
          <reference source="CVE" ref_id="CVE-2009-2625" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2625.html" />
    
    <description>The xerces-j2 packages provide the Apache Xerces2 Java Parser, a
high-performance XML parser. A Document Type Definition (DTD) defines the
legal syntax (and also which elements can be used) for certain types of
files, such as XML files.

A flaw was found in the way the Apache Xerces2 Java Parser processed the
SYSTEM identifier in DTDs. A remote attacker could provide a
specially-crafted XML file, which once parsed by an application using the
Apache Xerces2 Java Parser, would lead to a denial of service (application
hang due to excessive CPU use). (CVE-2009-2625)

Users should upgrade to these updated packages, which contain a backported
patch to correct this issue. Applications using the Apache Xerces2 Java
Parser must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-30" />
        <updated date="2009-11-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2625.html">CVE-2009-2625</cve>
                <bugzilla href="http://bugzilla.redhat.com/512921" id="512921">CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615014" comment="xerces-j2-demo is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615015" comment="xerces-j2-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615004" comment="xerces-j2-javadoc-xni is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615005" comment="xerces-j2-javadoc-xni is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615006" comment="xerces-j2-javadoc-other is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615007" comment="xerces-j2-javadoc-other is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615012" comment="xerces-j2-scripts is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615013" comment="xerces-j2-scripts is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615010" comment="xerces-j2-javadoc-apis is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615011" comment="xerces-j2-javadoc-apis is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615008" comment="xerces-j2-javadoc-impl is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615009" comment="xerces-j2-javadoc-impl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091615002" comment="xerces-j2 is earlier than 0:2.7.1-7jpp.2.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091615003" comment="xerces-j2 is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091619" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1619: dstat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1619-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1619.html" />
          <reference source="CVE" ref_id="CVE-2009-3894" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3894.html" />
    
    <description>Dstat is a versatile replacement for the vmstat, iostat, and netstat tools.
Dstat can be used for performance tuning tests, benchmarks, and
troubleshooting.

Robert Buchholz of the Gentoo Security Team reported a flaw in the Python
module search path used in dstat. If a local attacker could trick a
local user into running dstat from a directory containing a Python script
that is named like an importable module, they could execute arbitrary code
with the privileges of the user running dstat. (CVE-2009-3894)

All dstat users should upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-30" />
        <updated date="2009-11-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3894.html">CVE-2009-3894</cve>
                <bugzilla href="http://bugzilla.redhat.com/538459" id="538459">CVE-2009-3894 dstat insecure module search path</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091619002" comment="dstat is earlier than 0:0.6.6-3.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091619003" comment="dstat is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091620" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1620: bind security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1620-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1620.html" />
          <reference source="CVE" ref_id="CVE-2009-4022" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4022.html" />
    
    <description>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain
Name System (DNS) protocols. BIND includes a DNS server (named); a resolver
library (routines for applications to use when interfacing with DNS); and
tools for verifying that the DNS server is operating correctly.

Michael Sinatra discovered that BIND was incorrectly caching responses
without performing proper DNSSEC validation, when those responses were
received during the resolution of a recursive client query that requested
DNSSEC records but indicated that checking should be disabled. A remote
attacker could use this flaw to bypass the DNSSEC validation check and
perform a cache poisoning attack if the target BIND server was receiving
such client queries. (CVE-2009-4022)

All BIND users are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue. After installing the
update, the BIND daemon (named) will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-11-30" />
        <updated date="2009-11-30" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4022.html">CVE-2009-4022</cve>
                <bugzilla href="http://bugzilla.redhat.com/538744" id="538744">CVE-2009-4022 bind: cache poisoning using not validated DNSSEC responses</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620016" comment="bind-libbind-devel is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020005" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620012" comment="bind-devel is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020007" comment="bind-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620008" comment="bind-chroot is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020009" comment="bind-chroot is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620004" comment="bind-utils is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020011" comment="bind-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620010" comment="bind-sdb is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020017" comment="bind-sdb is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620002" comment="bind is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020003" comment="bind is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620006" comment="bind-libs is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020013" comment="bind-libs is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091620014" comment="caching-nameserver is earlier than 30:9.3.6-4.P1.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020015" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091625" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1625: expat security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1625-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1625.html" />
          <reference source="CVE" ref_id="CVE-2009-3560" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3560.html" />
          <reference source="CVE" ref_id="CVE-2009-3720" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3720.html" />
    
    <description>Expat is a C library written by James Clark for parsing XML documents.

Two buffer over-read flaws were found in the way Expat handled malformed
UTF-8 sequences when processing XML files. A specially-crafted XML file
could cause applications using Expat to crash while parsing the file.
(CVE-2009-3560, CVE-2009-3720)

All expat users should upgrade to these updated packages, which contain
backported patches to correct these issues. After installing the updated
packages, applications using the Expat library must be restarted for the
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-07" />
        <updated date="2009-12-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3560.html">CVE-2009-3560</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3720.html">CVE-2009-3720</cve>
                <bugzilla href="http://bugzilla.redhat.com/531697" id="531697">CVE-2009-3720 expat: buffer over-read and crash on XML with malformed UTF-8 sequences</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533174" id="533174">CVE-2009-3560 expat: buffer over-read and crash in big2_toUtf8() on XML with malformed UTF-8 sequences</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091625004" comment="expat-devel is earlier than 0:1.95.8-8.3.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091625005" comment="expat-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091625002" comment="expat is earlier than 0:1.95.8-8.3.el5_4.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091625003" comment="expat is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091625009" comment="expat-devel is earlier than 0:1.95.5-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091625010" comment="expat-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091625007" comment="expat is earlier than 0:1.95.5-6.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091625008" comment="expat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091625013" comment="expat-devel is earlier than 0:1.95.7-4.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091625010" comment="expat-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091625012" comment="expat is earlier than 0:1.95.7-4.el4_8.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091625008" comment="expat is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091642" version="503" class="patch">
      <metadata>
        <title>RHSA-2009:1642: acpid security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1642-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1642.html" />
          <reference source="CVE" ref_id="CVE-2009-4033" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4033.html" />
    
    <description>acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.

It was discovered that acpid could create its log file ("/var/log/acpid")
with random permissions on some systems. A local attacker could use this
flaw to escalate their privileges if the log file was created as
world-writable and with the setuid or setgid bit set. (CVE-2009-4033)

Please note that this flaw was due to a Red Hat-specific patch
(acpid-1.0.4-fd.patch) included in the Red Hat Enterprise Linux 5 acpid
package.

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-07" />
        <updated date="2009-12-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4033.html">CVE-2009-4033</cve>
                <bugzilla href="http://bugzilla.redhat.com/515062" id="515062">/var/log/acpid has improper permissions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/542926" id="542926">CVE-2009-4033 acpid: log file created with random permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091642002" comment="acpid is earlier than 0:1.0.4-9.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474003" comment="acpid is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091643" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1643: java-1.4.2-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1643-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1643.html" />
          <reference source="CVE" ref_id="CVE-2009-3867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3867.html" />
          <reference source="CVE" ref_id="CVE-2009-3868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3868.html" />
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html" />
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html" />
          <reference source="CVE" ref_id="CVE-2009-3872" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3872.html" />
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html" />
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html" />
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html" />
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html" />
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html" />
    
    <description>The IBM 1.4.2 SR13-FP3 Java release includes the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-3867, CVE-2009-3868, CVE-2009-3869,
CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875,
CVE-2009-3876, CVE-2009-3877)

All users of java-1.4.2-ibm are advised to upgrade to these updated
packages, which contain the IBM 1.4.2 SR13-FP3 Java release. All running
instances of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-07" />
        <updated date="2009-12-07" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3867.html">CVE-2009-3867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3868.html">CVE-2009-3868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3872.html">CVE-2009-3872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
                <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530057" id="530057">CVE-2009-3875 OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530062" id="530062">CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530063" id="530063">CVE-2009-3871 OpenJDK JRE AWT setBytePixels heap overflow (6872358)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530067" id="530067">CVE-2009-3874 OpenJDK ImageI/O JPEG heap overflow  (6874643)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532906" id="532906">CVE-2009-3872 JRE JPEG JFIF Decoder issue (6862969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533214" id="533214">CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533215" id="533215">CVE-2009-3868 java-1.5.0-sun, java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643002" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445003" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643004" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445005" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643010" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445013" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643006" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445011" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643012" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445009" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643014" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445015" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091643008" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13.3-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090445007" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091646" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1646: libtool security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1646-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1646.html" />
          <reference source="CVE" ref_id="CVE-2009-3736" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3736.html" />
    
    <description>GNU Libtool is a set of shell scripts which automatically configure UNIX,
Linux, and similar operating systems to generically build shared libraries.

A flaw was found in the way GNU Libtool's libltdl library looked for
modules to load. It was possible for libltdl to load and run modules from
an arbitrary library in the current working directory. If a local attacker
could trick a local user into running an application (which uses libltdl)
from an attacker-controlled directory containing a malicious Libtool
control file (.la), the attacker could possibly execute arbitrary code with
the privileges of the user running the application. (CVE-2009-3736)

All libtool users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the updated
packages, applications using the libltdl library must be restarted for the
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-08" />
        <updated date="2009-12-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3736.html">CVE-2009-3736</cve>
                <bugzilla href="http://bugzilla.redhat.com/537941" id="537941">CVE-2009-3736 libtool: libltdl may load and execute code from a library in the current directory</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646002" comment="libtool is earlier than 0:1.5.22-7.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646003" comment="libtool is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646006" comment="libtool-ltdl is earlier than 0:1.5.22-7.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646007" comment="libtool-ltdl is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646004" comment="libtool-ltdl-devel is earlier than 0:1.5.22-7.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646005" comment="libtool-ltdl-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646009" comment="libtool is earlier than 0:1.4.3-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646010" comment="libtool is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646011" comment="libtool-libs is earlier than 0:1.4.3-7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646012" comment="libtool-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646014" comment="libtool is earlier than 0:1.5.6-5.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646010" comment="libtool is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091646015" comment="libtool-libs is earlier than 0:1.5.6-5.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091646012" comment="libtool-libs is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091647" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1647: java-1.5.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1647-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1647.html" />
          <reference source="CVE" ref_id="CVE-2009-3867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3867.html" />
          <reference source="CVE" ref_id="CVE-2009-3868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3868.html" />
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html" />
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html" />
          <reference source="CVE" ref_id="CVE-2009-3872" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3872.html" />
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html" />
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html" />
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html" />
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html" />
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html" />
    
    <description>The IBM 1.5.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-3867, CVE-2009-3868, CVE-2009-3869,
CVE-2009-3871, CVE-2009-3872, CVE-2009-3873, CVE-2009-3874, CVE-2009-3875,
CVE-2009-3876, CVE-2009-3877)

All users of java-1.5.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.5.0 SR11 Java release. All running instances
of IBM Java must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-08" />
        <updated date="2009-12-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3867.html">CVE-2009-3867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3868.html">CVE-2009-3868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3872.html">CVE-2009-3872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
                <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530057" id="530057">CVE-2009-3875 OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530062" id="530062">CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530063" id="530063">CVE-2009-3871 OpenJDK JRE AWT setBytePixels heap overflow (6872358)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530067" id="530067">CVE-2009-3874 OpenJDK ImageI/O JPEG heap overflow  (6874643)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532906" id="532906">CVE-2009-3872 JRE JPEG JFIF Decoder issue (6862969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533214" id="533214">CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533215" id="533215">CVE-2009-3868 java-1.5.0-sun, java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647006" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016007" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647002" comment="java-1.5.0-ibm is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016003" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647010" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016009" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647012" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016015" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647014" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016017" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647008" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016005" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647004" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016011" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091647016" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.11-1jpp.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090016013" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091648" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1648: ntp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1648-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1648.html" />
          <reference source="CVE" ref_id="CVE-2009-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3563.html" />
    
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

Robin Park and Dmitri Vinokurov discovered a flaw in the way ntpd handled
certain malformed NTP packets. ntpd logged information about all such
packets and replied with an NTP packet that was treated as malformed when
received by another ntpd. A remote attacker could use this flaw to create
an NTP packet reply loop between two ntpd servers via a malformed packet
with a spoofed source IP address and port, causing ntpd on those servers to
use excessive amounts of CPU time and fill disk space with log messages.
(CVE-2009-3563)

All ntp users are advised to upgrade to this updated package, which
contains a backported patch to resolve this issue. After installing the
update, the ntpd daemon will restart automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-08" />
        <updated date="2009-12-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3563.html">CVE-2009-3563</cve>
                <bugzilla href="http://bugzilla.redhat.com/531213" id="531213">CVE-2009-3563 ntpd: DoS with mode 7 packets (VU#568372)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091648002" comment="ntp is earlier than 0:4.2.2p1-9.el5_4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046003" comment="ntp is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091648005" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046006" comment="ntp is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091651" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1651: ntp security update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1651-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1651.html" />
          <reference source="CVE" ref_id="CVE-2009-0159" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0159.html" />
          <reference source="CVE" ref_id="CVE-2009-3563" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3563.html" />
    
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

Robin Park and Dmitri Vinokurov discovered a flaw in the way ntpd handled
certain malformed NTP packets. ntpd logged information about all such
packets and replied with an NTP packet that was treated as malformed when
received by another ntpd. A remote attacker could use this flaw to create
an NTP packet reply loop between two ntpd servers via a malformed packet
with a spoofed source IP address and port, causing ntpd on those servers to
use excessive amounts of CPU time and fill disk space with log messages.
(CVE-2009-3563)

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq or, potentially, execute arbitrary code with
the privileges of the user running the ntpq command. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will restart automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-08" />
        <updated date="2009-12-08" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0159.html">CVE-2009-0159</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3563.html">CVE-2009-3563</cve>
                <bugzilla href="http://bugzilla.redhat.com/490617" id="490617">CVE-2009-0159 ntp: buffer overflow in ntpq</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/531213" id="531213">CVE-2009-3563 ntpd: DoS with mode 7 packets (VU#568372)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091651002" comment="ntp is earlier than 0:4.1.2-6.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046006" comment="ntp is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091657" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1657: flash-plugin security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1657-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1657.html" />
          <reference source="CVE" ref_id="CVE-2009-3794" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3794.html" />
          <reference source="CVE" ref_id="CVE-2009-3796" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3796.html" />
          <reference source="CVE" ref_id="CVE-2009-3797" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3797.html" />
          <reference source="CVE" ref_id="CVE-2009-3798" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3798.html" />
          <reference source="CVE" ref_id="CVE-2009-3799" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3799.html" />
          <reference source="CVE" ref_id="CVE-2009-3800" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3800.html" />
    
    <description>The flash-plugin package contains a Mozilla Firefox compatible Adobe Flash
Player web browser plug-in.

Multiple security flaws were found in the way Flash Player displayed
certain SWF content. An attacker could use these flaws to create a
specially-crafted SWF file that would cause flash-plugin to crash or,
possibly, execute arbitrary code when the victim loaded a page containing
the specially-crafted SWF content. (CVE-2009-3794, CVE-2009-3796,
CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)

All users of Adobe Flash Player should install this updated package, which
upgrades Flash Player to version 10.0.42.34.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-09" />
        <updated date="2009-12-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3794.html">CVE-2009-3794</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3796.html">CVE-2009-3796</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3797.html">CVE-2009-3797</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3798.html">CVE-2009-3798</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3799.html">CVE-2009-3799</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3800.html">CVE-2009-3800</cve>
                <bugzilla href="http://bugzilla.redhat.com/543857" id="543857">flash-plugin: multiple code execution flaws (APSB09-19) (CVE-2009-3794, CVE-2009-3796, CVE-2009-3797, CVE-2009-3798, CVE-2009-3799, CVE-2009-3800)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091657002" comment="flash-plugin is earlier than 0:10.0.42.34-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090332003" comment="flash-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091659" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1659: kvm security and bug fix update (Moderate)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1659-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1659.html" />
          <reference source="CVE" ref_id="CVE-2009-4031" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4031.html" />
    
    <description>KVM (Kernel-based Virtual Machine) is a full virtualization solution for
Linux on AMD64 and Intel 64 systems. KVM is a Linux kernel module built for
the standard Red Hat Enterprise Linux kernel.

On x86 platforms, the do_insn_fetch() function did not limit the amount of
instruction bytes fetched per instruction. Users in guest operating systems
could leverage this flaw to cause large latencies on SMP hosts that could
lead to a local denial of service on the host operating system. This
update fixes this issue by imposing the architecturally-defined 15 byte
length limit for instructions. (CVE-2009-4031)

This update also fixes the following bugs:

* performance problems occurred when using the qcow2 image format with the
qemu-kvm -drive "cache=none" option (the default setting when not specified
otherwise). This could cause guest operating system installations to take
hours. With this update, performance patches have been backported so that
using the qcow2 image format with the "cache=none" option no longer causes
performance issues. (BZ#520693)

* when using the virtual vm8086 mode, bugs in the emulated hardware task
switching implementation may have, in some situations, caused older guest
operating systems to malfunction. (BZ#532031)

* Windows Server 2003 guests (32-bit) with more than 4GB of memory may have
crashed during reboot when using the default qemu-kvm CPU settings.
(BZ#532043)

* with Red Hat Enterprise Virtualization, guests continued to run after
encountering disk read errors. This could have led to their file systems
becoming corrupted (but not the host's), notably in environments that use
networked storage. With this update, the qemu-kvm -drive "werror=stop"
option now applies not only to write errors but also to read errors: When
using this option, guests will pause on disk read and write errors.

By default, guests managed by Red Hat Enterprise Virtualization use the
"werror=stop" option. This option is not used by default for guests managed
by libvirt. (BZ#537334, BZ#540406)

* the para-virtualized block driver (virtio-blk) silently ignored read
errors when accessing disk images. With this update, the driver correctly
signals the read error to the guest. (BZ#537334)

All KVM users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Note: The procedure in the
Solution section must be performed before this update will take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-09" />
        <updated date="2009-12-09" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4031.html">CVE-2009-4031</cve>
                <bugzilla href="http://bugzilla.redhat.com/532031" id="532031">KVM does not implement proper support for hardware task linking when using vm8086 mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532043" id="532043">qemu aborted when restart 32bitwin23k with more than 4G mem in intel host.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537334" id="537334">O/S Filesystem Corruption with RHEL-5.4 on a RHEV Guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/540406" id="540406">RHEL5.4 VM image corruption with an IDE v-disk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/541160" id="541160">CVE-2009-4031 kernel: KVM: x86 emulator: limit instructions to 15 bytes</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091659004" comment="kvm-qemu-img is earlier than 0:83-105.el5_4.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465007" comment="kvm-qemu-img is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091659002" comment="kvm is earlier than 0:83-105.el5_4.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465003" comment="kvm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091659006" comment="kmod-kvm is earlier than 0:83-105.el5_4.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465005" comment="kmod-kvm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091659008" comment="kvm-tools is earlier than 0:83-105.el5_4.13" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091465009" comment="kvm-tools is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091670" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1670: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1670-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1670.html" />
          <reference source="CVE" ref_id="CVE-2009-3612" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3612.html" />
          <reference source="CVE" ref_id="CVE-2009-3620" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3620.html" />
          <reference source="CVE" ref_id="CVE-2009-3621" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3621.html" />
          <reference source="CVE" ref_id="CVE-2009-3726" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3726.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* NULL pointer dereference flaws in the r128 driver. Checks to test if the
Concurrent Command Engine state was initialized were missing in private
IOCTL functions. An attacker could use these flaws to cause a local denial
of service or escalate their privileges. (CVE-2009-3620, Important)

* a NULL pointer dereference flaw in the NFSv4 implementation. Several
NFSv4 file locking functions failed to check whether a file had been opened
on the server before performing locking operations on it. A local user on a
system with an NFSv4 share mounted could possibly use this flaw to cause a
denial of service or escalate their privileges. (CVE-2009-3726, Important)

* a flaw in tcf_fill_node(). A certain data structure in this function was
not initialized properly before being copied to user-space. This could lead
to an information leak. (CVE-2009-3612, Moderate)

* unix_stream_connect() did not check if a UNIX domain socket was in the
shutdown state. This could lead to a deadlock. A local, unprivileged user
could use this flaw to cause a denial of service. (CVE-2009-3621, Moderate)

Knowledgebase DOC-20536 has steps to mitigate NULL pointer dereference
flaws.

Bug fixes:

* frequently changing a CPU between online and offline caused a kernel
panic on some systems. (BZ#545583)

* for the LSI Logic LSI53C1030 Ultra320 SCSI controller, read commands sent
could receive incorrect data, preventing correct data transfer. (BZ#529308)

* pciehp could not detect PCI Express hot plug slots on some systems.
(BZ#530383)

* soft lockups: inotify race and contention on dcache_lock. (BZ#533822,
BZ#537019)

* priority ordered lists are now used for threads waiting for a given
mutex. (BZ#533858)

* a deadlock in DLM could cause GFS2 file systems to lock up. (BZ#533859)

* use-after-free bug in the audit subsystem crashed certain systems when
running usermod. (BZ#533861)

* on certain hardware configurations, a kernel panic when the Broadcom
iSCSI offload driver (bnx2i.ko and cnic.ko) was loaded. (BZ#537014)

* qla2xxx: Enabled MSI-X, and correctly handle the module parameter to
control it. This improves performance for certain systems. (BZ#537020)

* system crash when reading the cpuaffinity file on a system. (BZ#537346)

* suspend-resume problems on systems with lots of logical CPUs, e.g. BX-EX.
(BZ#539674)

* off-by-one error in the legacy PCI bus check. (BZ#539675)

* TSC was not made available on systems with multi-clustered APICs. This
could cause slow performance for time-sensitive applications. (BZ#539676)

* ACPI: ARB_DISABLE now disabled on platforms that do not need it.
(BZ#539677)

* fix node to core and power-aware scheduling issues, and a kernel panic
during boot on certain AMD Opteron processors. (BZ#539678, BZ#540469,
BZ#539680, BZ#539682)

* APIC timer interrupt issues on some AMD Opteron systems prevented
achieving full power savings. (BZ#539681)

* general OProfile support for some newer Intel processors. (BZ#539683)

* system crash during boot when NUMA is enabled on systems using MC and
kernel-xen. (BZ#539684)

* on some larger systems, performance issues due to a spinlock. (BZ#539685)

* APIC errors when IOMMU is enabled on some AMD Opteron systems.
(BZ#539687)

* on some AMD Opteron systems, repeatedly taking a CPU offline then online
caused a system hang. (BZ#539688)

* I/O page fault errors on some systems. (BZ#539689)

* certain memory configurations could cause the kernel-xen kernel to fail
to boot on some AMD Opteron systems. (BZ#539690)

* NMI watchdog is now disabled for offline CPUs. (BZ#539691)

* duplicate directories in /proc/acpi/processor/ on BX-EX systems.
(BZ#539692)

* links did not come up when using bnx2x with certain Broadcom devices.
(BZ#540381)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-15" />
        <updated date="2009-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3612.html">CVE-2009-3612</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3620.html">CVE-2009-3620</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3621.html">CVE-2009-3621</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3726.html">CVE-2009-3726</cve>
                <bugzilla href="http://bugzilla.redhat.com/528868" id="528868">CVE-2009-3612 kernel: tcf_fill_node() infoleak due to typo in 9ef1d4c7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529227" id="529227">CVE-2009-3726 kernel: nfsv4: kernel panic in nfs4_proc_lock()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529308" id="529308">[5.4]The errata 28 fix on LSI53C1030 hasn't been included yet. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529597" id="529597">CVE-2009-3620 kernel: r128 IOCTL NULL pointer dereferences when CCE state is uninitialised</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529626" id="529626">CVE-2009-3621 kernel: AF_UNIX: Fix deadlock on connecting to shutdown socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530383" id="530383">[5.3] PCIe hotplug slot detection failure [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533822" id="533822">CRM 1908390 - BUG: warning at fs/inotify.c:181/set_dentry_child_flags() [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533858" id="533858">threads on pthread_mutex_lock wake in fifo order, but posix specifies by priority [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533859" id="533859">dlm_recv deadlock under memory pressure while processing GFP_KERNEL locks. [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533861" id="533861">system crashes in audit_update_watch() [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537014" id="537014">Panic on boot when loading iscsid with broadcom NIC [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537019" id="537019">kernel: BUG: soft lockup with dcache_lock [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537020" id="537020">[QLogic 5.4.z bug] qla2xxx - enable MSI-X and correct/cleanup irq request code [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537346" id="537346">kernel: NULL pointer dereference in pci_bus_show_cpuaffinity() [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539675" id="539675">[Intel 5.5 FEAT] Add ability to access Nehalem uncore config space [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539676" id="539676">[Intel 5.5 FEAT] Support Intel multi-APIC-cluster systems [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539677" id="539677">[Intel 5.5 FEAT] ACPI: Disable ARB_DISABLE on platforms where it is not needed [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539678" id="539678">Fix node to core association [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539680" id="539680">Fix Power-aware scheduling [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539681" id="539681">Fix AMD erratum - server C1E [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539682" id="539682">Fix kernel panic while booting RHEL5 32-bit kernel [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539683" id="539683">[Intel 5.5 FEAT] Oprofile: Add support for arch perfmon - kernel component [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539684" id="539684">EXPERIMENTAL EX/MC: Fix Xen NUMA [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539685" id="539685">[Intel 5.5 FEAT] Fix spinlock issue which causes performance impact on large systems [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539687" id="539687">EXPERIMENTAL MC/EX: Fix APIC error IOMMU issues [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539688" id="539688">EXPERIMENTAL MC/EX: Issue when bringing CPU offline and online with 32-bit kernel [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539689" id="539689">EXPERIMENTAL EX/MC: AMD IOMMU Linux driver with latest BIOS has IO PAGE FAULTS [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539690" id="539690">EXPERIMENTAL MC/EX: Incorrect memory setup can cause Xen crash [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/539691" id="539691">[Intel 5.5 BUG] NMI and Watchdog are not disabled on CPU when CPU is off-lined [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/540381" id="540381">Broadcom Everest Dual port 10Gb with SFP+ (57711) NIC fails with no link [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/540469" id="540469">EXPERIMENTAL EX/MC: Fix node to core issue [rhel-5.4.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/545583" id="545583">kernel panic when doing cpu offline/online frequently on hp-dl785g5-01.rhts.eng.bos.redhat.com [rhel-5.4.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670004" comment="kernel-headers is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-headers is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670002" comment="kernel is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670024" comment="kernel-doc is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670020" comment="kernel-PAE-devel is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670008" comment="kernel-devel is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670012" comment="kernel-debug is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670016" comment="kernel-kdump is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670010" comment="kernel-xen-devel is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670014" comment="kernel-debug-devel is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670022" comment="kernel-PAE is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670018" comment="kernel-kdump-devel is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091670006" comment="kernel-xen is earlier than 0:2.6.18-164.9.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091671" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1671: kernel security and bug fix update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1671-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1671.html" />
          <reference source="CVE" ref_id="CVE-2009-2910" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-2910.html" />
          <reference source="CVE" ref_id="CVE-2009-3613" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3613.html" />
          <reference source="CVE" ref_id="CVE-2009-3620" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3620.html" />
          <reference source="CVE" ref_id="CVE-2009-3621" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3621.html" />
    
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a flaw was found in the Realtek r8169 Ethernet driver in the Linux
kernel. pci_unmap_single() presented a memory leak that could lead to IOMMU
space exhaustion and a system crash. An attacker on the local network could
trigger this flaw by using jumbo frames for large amounts of network
traffic. (CVE-2009-3613, Important)

* NULL pointer dereference flaws were found in the r128 driver in the Linux
kernel. Checks to test if the Concurrent Command Engine state was
initialized were missing in private IOCTL functions. An attacker could use
these flaws to cause a local denial of service or escalate their
privileges. (CVE-2009-3620, Important)

* an information leak was found in the Linux kernel. On AMD64 systems,
32-bit processes could access and read certain 64-bit registers by
temporarily switching themselves to 64-bit mode. (CVE-2009-2910, Moderate)

* the unix_stream_connect() function in the Linux kernel did not check if a
UNIX domain socket was in the shutdown state. This could lead to a
deadlock. A local, unprivileged user could use this flaw to cause a denial
of service. (CVE-2009-3621, Moderate)

This update also fixes the following bugs:

* an iptables rule with the recent module and a hit count value greater
than the ip_pkt_list_tot parameter (the default is 20), did not have any
effect over packets, as the hit count could not be reached. (BZ#529306)

* in environments that use dual-controller storage devices with the cciss
driver, Device-Mapper Multipath maps could not be detected and configured,
due to the cciss driver not exporting the bus attribute via sysfs. This
attribute is now exported. (BZ#529309)

* the kernel crashed with a divide error when a certain joystick was
attached. (BZ#532027)

* a bug in the mptctl_do_mpt_command() function in the mpt driver may have
resulted in crashes during boot on i386 systems with certain adapters using
the mpt driver, and also running the hugemem kernel. (BZ#533798)

* on certain hardware, the igb driver was unable to detect link statuses
correctly. This may have caused problems for network bonding, such as
failover not occurring. (BZ#534105)

* the RHSA-2009:1024 update introduced a regression. After updating to Red
Hat Enterprise Linux 4.8 and rebooting, network links often failed to be
brought up for interfaces using the forcedeth driver. "no link during
initialization" messages may have been logged. (BZ#534112)

* the RHSA-2009:1024 update introduced a second regression. On certain
systems, PS/2 keyboards failed to work. (BZ#537344)

* a bug in checksum offload calculations could have crashed the bnx2x
firmware when the iptable_nat module was loaded, causing network traffic
to stop. (BZ#537013)

* a check has been added to the IPv4 code to make sure that the routing
table data structure, rt, is not NULL, to help prevent future bugs in
functions that call ip_append_data() from being exploitable. (BZ#537016)

* possible kernel pointer dereferences on systems with several NFS mounts
(a mixture of "-o lock" and "-o nolock"), which in rare cases may have
caused a system crash, have been resolved. (BZ#537017)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-15" />
        <updated date="2009-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-2910.html">CVE-2009-2910</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3613.html">CVE-2009-3613</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3620.html">CVE-2009-3620</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3621.html">CVE-2009-3621</cve>
                <bugzilla href="http://bugzilla.redhat.com/526788" id="526788">CVE-2009-2910 kernel: x86_64 32 bit process register leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529137" id="529137">CVE-2009-3613 kernel: flood ping cause out-of-iommu error and panic when mtu larger than 1500</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529306" id="529306">kernel: ipt_recent: sanity check hit count [rhel-4.9] [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529309" id="529309">CCISS device-mapper-multipath support: missing sysfs attributes [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529597" id="529597">CVE-2009-3620 kernel: r128 IOCTL NULL pointer dereferences when CCE state is uninitialised</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/529626" id="529626">CVE-2009-3621 kernel: AF_UNIX: Fix deadlock on connecting to shutdown socket</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532027" id="532027">kernel hid-input.c divide error crash [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533798" id="533798">[Cisco/LSI 4.8.z bug] mptctl module dereferences a userspace address, triggering a crash [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/534105" id="534105">EL4.8: igb driver fails to detect link status change on SERDES interface [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/534112" id="534112">Upgrade from RHEL4U7 to U8 fails to bring up networking with forcedeth driver. [simple patch] [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537013" id="537013">bnx2x fails when iptables is on [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537016" id="537016">kernel: ipv4: make ip_append_data() handle NULL routing table [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537017" id="537017">NLM: Fix Oops in nlmclnt_mark_reclaim() [rhel-4.8.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/537344" id="537344">RHEL4.8 regression: PS/2 keyboard doesn't work on PRIMERGY TX120S1 [rhel-4.8.z]</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671002" comment="kernel is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671022" comment="kernel-doc is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-doc is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671004" comment="kernel-devel is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671016" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671018" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-hugemem is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671010" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671006" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel-largesmp-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671014" comment="kernel-xenU is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-xenU is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671008" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671020" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091671012" comment="kernel-smp is earlier than 0:2.6.9-89.0.18.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-smp is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091673" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1673: seamonkey security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
           <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1673-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1673.html" />
          <reference source="CVE" ref_id="CVE-2009-3979" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3979.html" />
          <reference source="CVE" ref_id="CVE-2009-3983" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3983.html" />
          <reference source="CVE" ref_id="CVE-2009-3984" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3984.html" />
    
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code with the privileges of the user running
SeaMonkey. (CVE-2009-3979)

A flaw was found in the SeaMonkey NT Lan Manager (NTLM) authentication
protocol implementation. If an attacker could trick a local user that has
NTLM credentials into visiting a specially-crafted web page, they could
send arbitrary requests, authenticated with the user's NTLM credentials, to
other applications on the user's system. (CVE-2009-3983)

A flaw was found in the way SeaMonkey displayed the SSL location bar
indicator. An attacker could create an unencrypted web page that appears
to be encrypted, possibly tricking the user into believing they are
visiting a secure page. (CVE-2009-3984)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-15" />
        <updated date="2009-12-15" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3979.html">CVE-2009-3979</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3983.html">CVE-2009-3983</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3984.html">CVE-2009-3984</cve>
                <bugzilla href="http://bugzilla.redhat.com/546694" id="546694">CVE-2009-3979 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546720" id="546720">CVE-2009-3983 Mozilla NTLM reflection vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546722" id="546722">CVE-2009-3984 Mozilla SSL spoofing with document.location and empty SSL response page</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673014" comment="seamonkey-nspr is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673018" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673016" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673004" comment="seamonkey-mail is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673002" comment="seamonkey is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673012" comment="seamonkey-devel is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673020" comment="seamonkey-nss is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-nss is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673010" comment="seamonkey-chat is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673006" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673008" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.48.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673026" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-51.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673024" comment="seamonkey-mail is earlier than 0:1.0.9-51.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673023" comment="seamonkey is earlier than 0:1.0.9-51.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673027" comment="seamonkey-devel is earlier than 0:1.0.9-51.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-devel is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673025" comment="seamonkey-chat is earlier than 0:1.0.9-51.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091673028" comment="seamonkey-js-debugger is earlier than 0:1.0.9-51.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-js-debugger is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091674" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1674: firefox security update (Critical)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
           <platform>Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1674-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1674.html" />
          <reference source="CVE" ref_id="CVE-2009-3979" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3979.html" />
          <reference source="CVE" ref_id="CVE-2009-3981" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3981.html" />
          <reference source="CVE" ref_id="CVE-2009-3983" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3983.html" />
          <reference source="CVE" ref_id="CVE-2009-3984" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3984.html" />
          <reference source="CVE" ref_id="CVE-2009-3985" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3985.html" />
          <reference source="CVE" ref_id="CVE-2009-3986" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3986.html" />
    
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code with the privileges of the user running
Firefox. (CVE-2009-3979, CVE-2009-3981, CVE-2009-3986)

A flaw was found in the Firefox NT Lan Manager (NTLM) authentication
protocol implementation. If an attacker could trick a local user that has
NTLM credentials into visiting a specially-crafted web page, they could
send arbitrary requests, authenticated with the user's NTLM credentials, to
other applications on the user's system. (CVE-2009-3983)

A flaw was found in the way Firefox displayed the SSL location bar
indicator. An attacker could create an unencrypted web page that appears to
be encrypted, possibly tricking the user into believing they are visiting a
secure page. (CVE-2009-3984)

A flaw was found in the way Firefox displayed blank pages after a user
navigates to an invalid address. If a user visits an attacker-controlled
web page that results in a blank page, the attacker could inject content
into that blank page, possibly tricking the user into believing they are
viewing a legitimate page. (CVE-2009-3985)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.16. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.16, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-16" />
        <updated date="2009-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3979.html">CVE-2009-3979</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3981.html">CVE-2009-3981</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3983.html">CVE-2009-3983</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3984.html">CVE-2009-3984</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3985.html">CVE-2009-3985</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3986.html">CVE-2009-3986</cve>
                <bugzilla href="http://bugzilla.redhat.com/546694" id="546694">CVE-2009-3979 Mozilla crash with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546713" id="546713">CVE-2009-3981 Mozilla crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546720" id="546720">CVE-2009-3983 Mozilla NTLM reflection vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546722" id="546722">CVE-2009-3984 Mozilla SSL spoofing with document.location and empty SSL response page</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546724" id="546724">CVE-2009-3986 Mozilla Chrome privilege escalation via window.opener</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/546726" id="546726">CVE-2009-3985 Mozilla URL spoofing via invalid document.location</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091674004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.16-2.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091674002" comment="xulrunner is earlier than 0:1.9.0.16-2.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091674006" comment="xulrunner-devel is earlier than 0:1.9.0.16-2.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091674008" comment="firefox is earlier than 0:3.0.16-1.el5_4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091674011" comment="firefox is earlier than 0:3.0.16-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
 
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091680" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1680: xpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1680-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1680.html" />
          <reference source="CVE" ref_id="CVE-2009-4035" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4035.html" />
    
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw
in Xpdf's Type 1 font parser. A specially-crafted PDF file with an embedded
Type 1 font could cause Xpdf to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-4035)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-16" />
        <updated date="2009-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4035.html">CVE-2009-4035</cve>
                <bugzilla href="http://bugzilla.redhat.com/541614" id="541614">CVE-2009-4035 xpdf: buffer overflow in FoFiType1::parse</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091680002" comment="xpdf is earlier than 1:3.00-23.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091681" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1681: gpdf security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1681-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1681.html" />
          <reference source="CVE" ref_id="CVE-2009-4035" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4035.html" />
    
    <description>GPdf is a viewer for Portable Document Format (PDF) files.

Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw
in GPdf's Type 1 font parser. A specially-crafted PDF file with an embedded
Type 1 font could cause GPdf to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-4035)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-16" />
        <updated date="2009-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4035.html">CVE-2009-4035</cve>
                <bugzilla href="http://bugzilla.redhat.com/541614" id="541614">CVE-2009-4035 xpdf: buffer overflow in FoFiType1::parse</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091681002" comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_8.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090458003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091682" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1682: kdegraphics security update (Important)</title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1682-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1682.html" />
          <reference source="CVE" ref_id="CVE-2009-4035" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-4035.html" />
    
    <description>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Petr Gajdos and Christian Kornacker of SUSE reported a buffer overflow flaw
in KPDF's Type 1 font parser. A specially-crafted PDF file with an embedded
Type 1 font could cause KPDF to crash or, possibly, execute arbitrary code
when opened. (CVE-2009-4035)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-16" />
        <updated date="2009-12-16" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-4035.html">CVE-2009-4035</cve>
                <bugzilla href="http://bugzilla.redhat.com/541614" id="541614">CVE-2009-4035 xpdf: buffer overflow in FoFiType1::parse</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002004" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091682002" comment="kdegraphics is earlier than 7:3.3.1-17.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431008" comment="kdegraphics is signed with Red Hat master key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091682004" comment="kdegraphics-devel is earlier than 7:3.3.1-17.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431010" comment="kdegraphics-devel is signed with Red Hat master key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091694" version="502" class="patch">
      <metadata>
        <title>RHSA-2009:1694: java-1.6.0-ibm security update (Critical)</title>
    <affected family="unix">
            <platform>Supplementary for Red Hat Enterprise Linux 5</platform>
         </affected>
    <reference source="RHSA" ref_id="RHSA-2009:1694-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1694.html" />
          <reference source="CVE" ref_id="CVE-2009-0217" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-0217.html" />
          <reference source="CVE" ref_id="CVE-2009-3555" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3555.html" />
          <reference source="CVE" ref_id="CVE-2009-3865" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3865.html" />
          <reference source="CVE" ref_id="CVE-2009-3866" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3866.html" />
          <reference source="CVE" ref_id="CVE-2009-3867" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3867.html" />
          <reference source="CVE" ref_id="CVE-2009-3868" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3868.html" />
          <reference source="CVE" ref_id="CVE-2009-3869" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3869.html" />
          <reference source="CVE" ref_id="CVE-2009-3871" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3871.html" />
          <reference source="CVE" ref_id="CVE-2009-3872" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3872.html" />
          <reference source="CVE" ref_id="CVE-2009-3873" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3873.html" />
          <reference source="CVE" ref_id="CVE-2009-3874" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3874.html" />
          <reference source="CVE" ref_id="CVE-2009-3875" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3875.html" />
          <reference source="CVE" ref_id="CVE-2009-3876" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3876.html" />
          <reference source="CVE" ref_id="CVE-2009-3877" ref_url="https://www.redhat.com/security/data/cve/CVE-2009-3877.html" />
    
    <description>The IBM 1.6.0 Java release includes the IBM Java 2 Runtime Environment and
the IBM Java 2 Software Development Kit.

This update fixes several vulnerabilities in the IBM Java 2 Runtime
Environment and the IBM Java 2 Software Development Kit. These
vulnerabilities are summarized on the IBM "Security alerts" page listed in
the References section. (CVE-2009-0217, CVE-2009-3865, CVE-2009-3866,
CVE-2009-3867, CVE-2009-3868, CVE-2009-3869, CVE-2009-3871, CVE-2009-3872,
CVE-2009-3873, CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877)

All users of java-1.6.0-ibm are advised to upgrade to these updated
packages, containing the IBM 1.6.0 SR7 Java release. All running instances
of IBM Java must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-12-23" />
        <updated date="2009-12-23" />
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-0217.html">CVE-2009-0217</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3555.html">CVE-2009-3555</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3865.html">CVE-2009-3865</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3866.html">CVE-2009-3866</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3867.html">CVE-2009-3867</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3868.html">CVE-2009-3868</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3869.html">CVE-2009-3869</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3871.html">CVE-2009-3871</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3872.html">CVE-2009-3872</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3873.html">CVE-2009-3873</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3874.html">CVE-2009-3874</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3875.html">CVE-2009-3875</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3876.html">CVE-2009-3876</cve>
            <cve href="https://www.redhat.com/security/data/cve/CVE-2009-3877.html">CVE-2009-3877</cve>
                <bugzilla href="http://bugzilla.redhat.com/511915" id="511915">CVE-2009-0217 xmlsec1, mono, xml-security-c, xml-security-1.3.0-1jpp.ep1.*: XMLDsig HMAC-based signatures spoofing and authentication bypass</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530053" id="530053">CVE-2009-3873 OpenJDK JPEG Image Writer quantization problem (6862968)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530057" id="530057">CVE-2009-3875 OpenJDK MessageDigest.isEqual introduces timing attack vulnerabilities  (6863503)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530061" id="530061">CVE-2009-3876 OpenJDK ASN.1/DER input stream parser denial of service (6864911) CVE-2009-3877</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530062" id="530062">CVE-2009-3869 OpenJDK JRE AWT setDifflCM stack overflow (6872357)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530063" id="530063">CVE-2009-3871 OpenJDK JRE AWT setBytePixels heap overflow (6872358)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/530067" id="530067">CVE-2009-3874 OpenJDK ImageI/O JPEG heap overflow  (6874643)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/532906" id="532906">CVE-2009-3872 JRE JPEG JFIF Decoder issue (6862969)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533211" id="533211">CVE-2009-3865 java-1.6.0-sun: ACE in JRE Deployment Toolkit (6869752)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533212" id="533212">CVE-2009-3866 java-1.6.0-sun: Privilege escalation in the Java Web Start Installer  (6872824)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533214" id="533214">CVE-2009-3867 java-1.5.0-sun, java-1.6.0-sun: Stack-based buffer overflow via a long file: URL argument (6854303)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/533215" id="533215">CVE-2009-3868 java-1.5.0-sun, java-1.6.0-sun: Privilege escalation via crafted image file due improper color profiles parsing (6862970)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_extras</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090002001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694010" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015011" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694002" comment="java-1.6.0-ibm is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015003" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694016" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015009" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694012" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015007" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694014" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015017" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694004" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015005" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694008" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015013" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091694006" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.7-1jpp.2.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090015015" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
</definitions>

<tests>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090002001" version="502" comment="Red Hat Enterprise Linux 5 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090002002" version="502" comment="thunderbird is earlier than 0:2.0.0.19-1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090002003" version="502" comment="thunderbird is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090002004" version="502" comment="Red Hat Enterprise Linux 4 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090002005" version="502" comment="thunderbird is earlier than 0:1.5.0.12-18.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090002006" version="502" comment="thunderbird is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090003002" version="502" comment="xen is earlier than 0:3.0.3-64.el5_2.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090003003" version="502" comment="xen is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090003002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090003004" version="502" comment="xen-libs is earlier than 0:3.0.3-64.el5_2.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090003005" version="502" comment="xen-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090003003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090003006" version="502" comment="xen-devel is earlier than 0:3.0.3-64.el5_2.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090003003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090003007" version="502" comment="xen-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090003004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004002" version="502" comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004003" version="502" comment="openssl097a is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004004" version="502" comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004005" version="502" comment="openssl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004006" version="502" comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004007" version="502" comment="openssl-perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004008" version="502" comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004009" version="502" comment="openssl-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004010" version="502" comment="Red Hat Enterprise Linux 3 is installed" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002001" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004011" version="502" comment="openssl is earlier than 0:0.9.7a-33.25" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004012" version="502" comment="openssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004013" version="502" comment="openssl-perl is earlier than 0:0.9.7a-33.25" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004014" version="502" comment="openssl-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004015" version="502" comment="openssl-devel is earlier than 0:0.9.7a-33.25" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004016" version="502" comment="openssl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004017" version="502" comment="openssl096b is earlier than 0:0.9.6b-16.49" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004018" version="502" comment="openssl096b is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004020" version="502" comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004021" version="502" comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004022" version="502" comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004010" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090004023" version="502" comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090004006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090004011" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005002" version="502" comment="gnome-vfs2 is earlier than 0:2.2.5-2E.3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090005003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005003" version="502" comment="gnome-vfs2 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005004" version="502" comment="gnome-vfs2-devel is earlier than 0:2.2.5-2E.3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090005003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005005" version="502" comment="gnome-vfs2-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005007" version="502" comment="gnome-vfs2 is earlier than 0:2.8.2-8.7.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090005005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005008" version="502" comment="gnome-vfs2-smb is earlier than 0:2.8.2-8.7.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090005005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005009" version="502" comment="gnome-vfs2-smb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090005010" version="502" comment="gnome-vfs2-devel is earlier than 0:2.8.2-8.7.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090005003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090005005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090008002" version="502" comment="dbus is earlier than 0:1.0.0-7.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090008002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090008003" version="502" comment="dbus is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090008002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090008004" version="502" comment="dbus-x11 is earlier than 0:1.0.0-7.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090008003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090008005" version="502" comment="dbus-x11 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090008003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090008006" version="502" comment="dbus-devel is earlier than 0:1.0.0-7.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090008004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090008003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090008007" version="502" comment="dbus-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090008004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090010002" version="502" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090010004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090010003" version="502" comment="squirrelmail is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090010005" version="502" comment="squirrelmail is earlier than 0:1.4.8-8.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090010006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090010006" version="502" comment="squirrelmail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090010008" version="502" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090010008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090011002" version="502" comment="lcms is earlier than 0:1.15-1.2.2.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090011003" version="502" comment="lcms is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090011004" version="502" comment="lcms-devel is earlier than 0:1.15-1.2.2.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090011005" version="502" comment="lcms-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090011006" version="502" comment="python-lcms is earlier than 0:1.15-1.2.2.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090011003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090011007" version="502" comment="python-lcms is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012002" version="502" comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090012004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012003" version="502" comment="netpbm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012004" version="502" comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090012004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012005" version="502" comment="netpbm-progs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012006" version="502" comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090012004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012007" version="502" comment="netpbm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012009" version="502" comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090012006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012010" version="502" comment="netpbm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012011" version="502" comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090012006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012012" version="502" comment="netpbm-progs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012013" version="502" comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090012006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090012014" version="502" comment="netpbm-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090012004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013002" version="502" comment="avahi is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013003" version="502" comment="avahi is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013004" version="502" comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013005" version="502" comment="avahi-compat-libdns_sd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013006" version="502" comment="avahi-tools is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013007" version="502" comment="avahi-tools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013008" version="502" comment="avahi-glib is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013009" version="502" comment="avahi-glib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013010" version="502" comment="avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013011" version="502" comment="avahi-compat-howl-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013012" version="502" comment="avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013013" version="502" comment="avahi-qt3-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013014" version="502" comment="avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013015" version="502" comment="avahi-qt3 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013016" version="502" comment="avahi-devel is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013017" version="502" comment="avahi-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013018" version="502" comment="avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013019" version="502" comment="avahi-glib-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013020" version="502" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013021" version="502" comment="avahi-compat-libdns_sd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013022" version="502" comment="avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090013003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090013023" version="502" comment="avahi-compat-howl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090013012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014002" version="502" comment="kernel is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014003" version="502" comment="kernel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014004" version="502" comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014005" version="502" comment="kernel-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014006" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014007" version="502" comment="kernel-largesmp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014008" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014009" version="502" comment="kernel-largesmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014010" version="502" comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014011" version="502" comment="kernel-smp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014012" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014013" version="502" comment="kernel-smp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014014" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014015" version="502" comment="kernel-xenU-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014016" version="502" comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014017" version="502" comment="kernel-xenU is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014018" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014019" version="502" comment="kernel-hugemem is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014020" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014021" version="502" comment="kernel-hugemem-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014022" version="502" comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090014003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090014023" version="502" comment="kernel-doc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015002" version="502" comment="java-1.6.0-ibm is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015003" version="502" comment="java-1.6.0-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015004" version="502" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015005" version="502" comment="java-1.6.0-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015006" version="502" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015007" version="502" comment="java-1.6.0-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015008" version="502" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015009" version="502" comment="java-1.6.0-ibm-accessibility is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015010" version="502" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015011" version="502" comment="java-1.6.0-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015012" version="502" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015013" version="502" comment="java-1.6.0-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015014" version="502" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015015" version="502" comment="java-1.6.0-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015016" version="502" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.3-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090015004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090015017" version="502" comment="java-1.6.0-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016002" version="502" comment="java-1.5.0-ibm is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016003" version="502" comment="java-1.5.0-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016004" version="502" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016005" version="502" comment="java-1.5.0-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016006" version="502" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016007" version="502" comment="java-1.5.0-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016008" version="502" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016009" version="502" comment="java-1.5.0-ibm-accessibility is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016010" version="502" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016011" version="502" comment="java-1.5.0-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016012" version="502" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016013" version="502" comment="java-1.5.0-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016014" version="502" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016015" version="502" comment="java-1.5.0-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016016" version="502" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.9-1jpp.2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090016004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090016017" version="502" comment="java-1.5.0-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090018002" version="502" comment="xterm is earlier than 0:215-5.el5_2.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090018004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090018003" version="502" comment="xterm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090018005" version="502" comment="xterm is earlier than 0:179-11.EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090018006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090018006" version="502" comment="xterm is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090018008" version="502" comment="xterm is earlier than 0:192-8.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090018002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090018008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020002" version="502" comment="bind is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020003" version="502" comment="bind is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020004" version="502" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020005" version="502" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020006" version="502" comment="bind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020007" version="502" comment="bind-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020008" version="502" comment="bind-chroot is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020009" version="502" comment="bind-chroot is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020010" version="502" comment="bind-utils is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020011" version="502" comment="bind-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020012" version="502" comment="bind-libs is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020013" version="502" comment="bind-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020014" version="502" comment="caching-nameserver is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020015" version="502" comment="caching-nameserver is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020016" version="502" comment="bind-sdb is earlier than 30:9.3.4-6.0.3.P1.el5_2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020017" version="502" comment="bind-sdb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020019" version="502" comment="bind is earlier than 20:9.2.4-23.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020020" version="502" comment="bind is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020021" version="502" comment="bind-utils is earlier than 20:9.2.4-23.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020022" version="502" comment="bind-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020023" version="502" comment="bind-devel is earlier than 20:9.2.4-23.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020024" version="502" comment="bind-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020025" version="502" comment="bind-libs is earlier than 20:9.2.4-23.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020026" version="502" comment="bind-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020027" version="502" comment="bind-chroot is earlier than 20:9.2.4-23.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020028" version="502" comment="bind-chroot is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020030" version="502" comment="bind is earlier than 20:9.2.4-30.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020031" version="502" comment="bind-utils is earlier than 20:9.2.4-30.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020032" version="502" comment="bind-devel is earlier than 20:9.2.4-30.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020033" version="502" comment="bind-chroot is earlier than 20:9.2.4-30.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090020034" version="502" comment="bind-libs is earlier than 20:9.2.4-30.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090020008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090045002" version="503" comment="libvirt is earlier than 0:0.3.3-14.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090045002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090045003" version="503" comment="libvirt is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090045002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090045004" version="503" comment="libvirt-python is earlier than 0:0.3.3-14.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090045003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090045005" version="503" comment="libvirt-python is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090045003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090045006" version="503" comment="libvirt-devel is earlier than 0:0.3.3-14.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090045004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090045003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090045007" version="503" comment="libvirt-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090045004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090046002" version="502" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090046002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090046004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090046003" version="502" comment="ntp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090046002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090046005" version="502" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090046002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090046006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090046006" version="502" comment="ntp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090046002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090057002" version="502" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090057004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090057005" version="502" comment="squirrelmail is earlier than 0:1.4.8-9.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090057006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090057008" version="502" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090057008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090205002" version="503" comment="dovecot is earlier than 0:1.0.7-7.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090205002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090205003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090205003" version="503" comment="dovecot is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090205002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225002" version="504" comment="kernel is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225003" version="504" comment="kernel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225004" version="504" comment="kernel-headers is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225005" version="504" comment="kernel-headers is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225006" version="504" comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225007" version="504" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225008" version="504" comment="kernel-xen is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225009" version="504" comment="kernel-xen is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225010" version="504" comment="kernel-debug is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225011" version="504" comment="kernel-debug is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225012" version="504" comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225013" version="504" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225014" version="504" comment="kernel-devel is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225015" version="504" comment="kernel-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225016" version="504" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225017" version="504" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225018" version="504" comment="kernel-kdump is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225019" version="504" comment="kernel-kdump is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225020" version="504" comment="kernel-PAE is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225021" version="504" comment="kernel-PAE is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225022" version="504" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225023" version="504" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225024" version="504" comment="kernel-doc is earlier than 0:2.6.18-128.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090225003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090225025" version="504" comment="kernel-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256002" version="502" comment="xulrunner is earlier than 0:1.9.0.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256003" version="502" comment="xulrunner is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256004" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256005" version="502" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256006" version="502" comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256007" version="502" comment="xulrunner-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256008" version="502" comment="firefox is earlier than 0:3.0.6-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256009" version="502" comment="firefox is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256010" version="502" comment="nss is earlier than 0:3.12.2.0-4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256011" version="502" comment="nss is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256012" version="502" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256013" version="502" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256014" version="502" comment="nss-tools is earlier than 0:3.12.2.0-4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256015" version="502" comment="nss-tools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256016" version="502" comment="nss-devel is earlier than 0:3.12.2.0-4.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256017" version="502" comment="nss-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256019" version="502" comment="firefox is earlier than 0:3.0.6-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256020" version="502" comment="firefox is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256021" version="502" comment="nss is earlier than 0:3.12.2.0-3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256022" version="502" comment="nss is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256023" version="502" comment="nss-devel is earlier than 0:3.12.2.0-3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256024" version="502" comment="nss-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256025" version="502" comment="nss-tools is earlier than 0:3.12.2.0-3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090256009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090256026" version="502" comment="nss-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257003" version="502" comment="seamonkey is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257004" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257005" version="502" comment="seamonkey-dom-inspector is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257006" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257007" version="502" comment="seamonkey-nspr-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257008" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257009" version="502" comment="seamonkey-js-debugger is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257010" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257011" version="502" comment="seamonkey-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257012" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257013" version="502" comment="seamonkey-mail is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257014" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257015" version="502" comment="seamonkey-nss is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257016" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257017" version="502" comment="seamonkey-chat is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257018" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257019" version="502" comment="seamonkey-nspr is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257020" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257021" version="502" comment="seamonkey-nss-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257023" version="502" comment="seamonkey is earlier than 0:1.0.9-35.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257024" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257025" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257026" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257027" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090257028" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090257005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090258002" version="502" comment="thunderbird is earlier than 0:2.0.0.21-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090258004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090258005" version="502" comment="thunderbird is earlier than 0:1.5.0.12-19.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090258006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090259002" version="502" comment="mod_auth_mysql is earlier than 1:3.0.0-3.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090259002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090259003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090259003" version="502" comment="mod_auth_mysql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090259002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261002" version="502" comment="vnc is earlier than 0:4.1.2-14.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090261004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261003" version="502" comment="vnc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261004" version="502" comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090261004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261005" version="502" comment="vnc-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261007" version="502" comment="vnc is earlier than 0:4.0-0.beta4.1.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090261006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261008" version="502" comment="vnc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261009" version="502" comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090261006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261010" version="502" comment="vnc-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261012" version="502" comment="vnc is earlier than 0:4.0-12.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090261008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090261013" version="502" comment="vnc-server is earlier than 0:4.0-12.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090261003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090261008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264002" version="502" comment="kernel is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264004" version="502" comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264006" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264008" version="502" comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264010" version="502" comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264012" version="502" comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264014" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264016" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264018" version="502" comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090264024" version="502" comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090264003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090267002" version="502" comment="sudo is earlier than 0:1.6.9p17-3.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090267002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090267003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090267003" version="502" comment="sudo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090267002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090269002" version="502" comment="gstreamer-plugins is earlier than 0:0.6.0-19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090269002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090269003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090269003" version="502" comment="gstreamer-plugins is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090269002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090269004" version="502" comment="gstreamer-plugins-devel is earlier than 0:0.6.0-19" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090269003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090269003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090269005" version="502" comment="gstreamer-plugins-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090269003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090270002" version="502" comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090269002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090270003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090270004" version="502" comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090269003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090270003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090271002" version="503" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090271003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090271003" version="503" comment="gstreamer-plugins-good is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090271004" version="503" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090271003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090271003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090271005" version="503" comment="gstreamer-plugins-good-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090271003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090275002" version="502" comment="imap is earlier than 1:2002d-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090275002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090275003" version="502" comment="imap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090275002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090275004" version="502" comment="imap-devel is earlier than 1:2002d-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090275003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090275005" version="502" comment="imap-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090275003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090275006" version="502" comment="imap-utils is earlier than 1:2002d-15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090275004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090275003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090275007" version="502" comment="imap-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090275004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295002" version="502" comment="net-snmp is earlier than 0:5.0.9-2.30E.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090295003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295003" version="502" comment="net-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295004" version="502" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090295003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295005" version="502" comment="net-snmp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295006" version="502" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090295003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295007" version="502" comment="net-snmp-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295008" version="502" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090295003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295009" version="502" comment="net-snmp-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295010" version="502" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.27" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090295003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090295011" version="502" comment="net-snmp-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296002" version="502" comment="icu is earlier than 0:3.6-5.11.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090296003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296003" version="502" comment="icu is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296004" version="502" comment="libicu-doc is earlier than 0:3.6-5.11.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090296003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296005" version="502" comment="libicu-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296006" version="502" comment="libicu is earlier than 0:3.6-5.11.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090296003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296007" version="502" comment="libicu is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296008" version="502" comment="libicu-devel is earlier than 0:3.6-5.11.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090296003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090296009" version="502" comment="libicu-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090308002" version="502" comment="cups is earlier than 1:1.1.17-13.3.56" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090308003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090308003" version="502" comment="cups is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090308004" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.56" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090308003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090308005" version="502" comment="cups-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090308006" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.56" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090308003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090308007" version="502" comment="cups-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313002" version="502" comment="wireshark is earlier than 0:1.0.6-2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090313004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313003" version="502" comment="wireshark is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313004" version="502" comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090313004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313005" version="502" comment="wireshark-gnome is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313007" version="502" comment="wireshark is earlier than 0:1.0.6-EL3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090313006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313008" version="502" comment="wireshark is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313009" version="502" comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090313006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313010" version="502" comment="wireshark-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313012" version="502" comment="wireshark is earlier than 0:1.0.6-2.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090313008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090313013" version="502" comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090313008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090315002" version="502" comment="firefox is earlier than 0:3.0.7-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090315004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090315004" version="502" comment="xulrunner is earlier than 0:1.9.0.7-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090315005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090315006" version="502" comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090315005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090315008" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090315005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090315011" version="502" comment="firefox is earlier than 0:3.0.7-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090315007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325004" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325006" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325008" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325010" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325012" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325014" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325016" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325018" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325020" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325023" version="502" comment="seamonkey is earlier than 0:1.0.9-38.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325024" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325025" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325026" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325027" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090325028" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090325005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326002" version="502" comment="kernel is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326004" version="502" comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326006" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326008" version="502" comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326010" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326012" version="502" comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326014" version="502" comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326016" version="502" comment="kernel-kdump is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326018" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090326024" version="502" comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090326003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329002" version="503" comment="freetype is earlier than 0:2.1.4-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329003" version="503" comment="freetype is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329004" version="503" comment="freetype-demos is earlier than 0:2.1.4-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329005" version="503" comment="freetype-demos is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329006" version="503" comment="freetype-devel is earlier than 0:2.1.4-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329007" version="503" comment="freetype-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329008" version="503" comment="freetype-utils is earlier than 0:2.1.4-12.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329009" version="503" comment="freetype-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329011" version="503" comment="freetype is earlier than 0:2.1.9-10.el4.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329012" version="503" comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329013" version="503" comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090329014" version="503" comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090329005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331002" version="502" comment="kernel is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331004" version="502" comment="kernel-devel is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331006" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331008" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331010" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331012" version="502" comment="kernel-smp is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331014" version="502" comment="kernel-xenU is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331016" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090331022" version="502" comment="kernel-doc is earlier than 0:2.6.9-78.0.17.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090331003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090332002" version="502" comment="flash-plugin is earlier than 0:10.0.22.87-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090332003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090332003" version="502" comment="flash-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090332002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333002" version="502" comment="libpng is earlier than 2:1.2.10-7.1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090333004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333003" version="502" comment="libpng is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333004" version="502" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090333004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333005" version="502" comment="libpng-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333007" version="502" comment="libpng is earlier than 2:1.2.7-3.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090333006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333008" version="502" comment="libpng is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333009" version="502" comment="libpng-devel is earlier than 2:1.2.7-3.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090333006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333010" version="502" comment="libpng-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333011" version="502" comment="libpng10 is earlier than 0:1.0.16-3.el4_7.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090333007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333012" version="502" comment="libpng10 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333013" version="502" comment="libpng10-devel is earlier than 0:1.0.16-3.el4_7.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090333007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090333014" version="502" comment="libpng10-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090336002" version="502" comment="glib2 is earlier than 0:2.12.3-4.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090336002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090336003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090336003" version="502" comment="glib2 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090336002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090336004" version="502" comment="glib2-devel is earlier than 0:2.12.3-4.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090336003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090336003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090336005" version="502" comment="glib2-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090336003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337002" version="502" comment="php is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337003" version="502" comment="php is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337004" version="502" comment="php-imap is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337005" version="502" comment="php-imap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337006" version="502" comment="php-pgsql is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337007" version="502" comment="php-pgsql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337008" version="502" comment="php-odbc is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337009" version="502" comment="php-odbc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337010" version="502" comment="php-mysql is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337011" version="502" comment="php-mysql is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337012" version="502" comment="php-devel is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337013" version="502" comment="php-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337014" version="502" comment="php-ldap is earlier than 0:4.3.2-51.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337015" version="502" comment="php-ldap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337017" version="502" comment="php is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337018" version="502" comment="php-imap is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337019" version="502" comment="php-gd is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337020" version="502" comment="php-gd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337021" version="502" comment="php-domxml is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337022" version="502" comment="php-domxml is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337023" version="502" comment="php-mysql is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337024" version="502" comment="php-devel is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337025" version="502" comment="php-ldap is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337026" version="502" comment="php-pear is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337027" version="502" comment="php-pear is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337028" version="502" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337029" version="502" comment="php-xmlrpc is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337030" version="502" comment="php-odbc is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337031" version="502" comment="php-mbstring is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337032" version="502" comment="php-mbstring is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337033" version="502" comment="php-pgsql is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337034" version="502" comment="php-snmp is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337035" version="502" comment="php-snmp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337036" version="502" comment="php-ncurses is earlier than 0:4.3.9-3.22.15" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090337005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090337037" version="502" comment="php-ncurses is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338002" version="502" comment="php is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338003" version="502" comment="php is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338004" version="502" comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338005" version="502" comment="php-xmlrpc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338006" version="502" comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338007" version="502" comment="php-snmp is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337014" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338008" version="502" comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338009" version="502" comment="php-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338010" version="502" comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338011" version="502" comment="php-odbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338012" version="502" comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338013" version="502" comment="php-cli is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338014" version="502" comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338015" version="502" comment="php-gd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338016" version="502" comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338017" version="502" comment="php-soap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338018" version="502" comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338019" version="502" comment="php-ncurses is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338020" version="502" comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338021" version="502" comment="php-pgsql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338022" version="502" comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338023" version="502" comment="php-dba is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338024" version="502" comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338025" version="502" comment="php-bcmath is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338026" version="502" comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338027" version="502" comment="php-mbstring is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337013" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338028" version="502" comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338029" version="502" comment="php-xml is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338015" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338030" version="502" comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338031" version="502" comment="php-pdo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338016" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338032" version="502" comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338033" version="502" comment="php-mysql is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338034" version="502" comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338035" version="502" comment="php-imap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338036" version="502" comment="php-common is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338037" version="502" comment="php-common is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090338019" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338038" version="502" comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090338003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090338039" version="502" comment="php-ldap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090337008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090339002" version="502" comment="lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090339003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090339004" version="502" comment="python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090339003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090339006" version="502" comment="lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090011003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090339003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090340002" version="502" comment="libpng is earlier than 2:1.2.2-29" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090340003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090340004" version="502" comment="libpng-devel is earlier than 2:1.2.2-29" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090340003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090340006" version="502" comment="libpng10 is earlier than 0:1.0.13-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090340004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090340008" version="502" comment="libpng10-devel is earlier than 0:1.0.13-20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090333005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090340004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341002" version="502" comment="curl is earlier than 0:7.15.5-2.1.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090341004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341003" version="502" comment="curl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341004" version="502" comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090341004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341005" version="502" comment="curl-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341007" version="502" comment="curl is earlier than 0:7.10.6-9.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090341006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341008" version="502" comment="curl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341009" version="502" comment="curl-devel is earlier than 0:7.10.6-9.rhel3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090341006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341010" version="502" comment="curl-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341012" version="502" comment="curl is earlier than 0:7.12.1-11.1.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090341008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090341013" version="502" comment="curl-devel is earlier than 0:7.12.1-11.1.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090341003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090341008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344002" version="502" comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090344004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344003" version="502" comment="libsoup is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344004" version="502" comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090344004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344005" version="502" comment="libsoup-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344007" version="502" comment="libsoup is earlier than 0:2.2.1-4.el4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090344006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344008" version="502" comment="libsoup is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344009" version="502" comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090344006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344010" version="502" comment="libsoup-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344011" version="502" comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090344007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344012" version="502" comment="evolution28-libsoup is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344013" version="502" comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090344007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090344014" version="502" comment="evolution28-libsoup-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090344005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345002" version="502" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345003" version="502" comment="ghostscript is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345004" version="502" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345005" version="502" comment="ghostscript-gtk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345006" version="502" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345007" version="502" comment="ghostscript-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345009" version="502" comment="ghostscript is earlier than 0:7.05-32.1.17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345010" version="502" comment="ghostscript is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345011" version="502" comment="hpijs is earlier than 0:1.3-32.1.17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345012" version="502" comment="hpijs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345013" version="502" comment="ghostscript-devel is earlier than 0:7.05-32.1.17" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345014" version="502" comment="ghostscript-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345016" version="502" comment="ghostscript is earlier than 0:7.07-33.2.el4_7.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345017" version="502" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345018" version="502" comment="ghostscript-gtk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090345019" version="502" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090345009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090352002" version="502" comment="gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090352002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090352003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090352003" version="502" comment="gstreamer-plugins-base is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090352002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090352004" version="502" comment="gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090352003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090352003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090352005" version="502" comment="gstreamer-plugins-base-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090352003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354002" version="502" comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354003" version="502" comment="evolution-data-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354004" version="502" comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354005" version="502" comment="evolution-data-server-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354006" version="502" comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090354004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354007" version="502" comment="evolution-data-server-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354009" version="502" comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090354006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354010" version="502" comment="evolution28-evolution-data-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354011" version="502" comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090354006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090354012" version="502" comment="evolution28-evolution-data-server-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355002" version="502" comment="evolution is earlier than 0:2.0.2-41.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090355002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090355003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355003" version="502" comment="evolution is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090355002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355004" version="502" comment="evolution-devel is earlier than 0:2.0.2-41.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090355003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090355003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355005" version="502" comment="evolution-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090355003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355006" version="502" comment="evolution-data-server is earlier than 0:1.0.2-14.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090355004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355007" version="502" comment="evolution-data-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355008" version="502" comment="evolution-data-server-devel is earlier than 0:1.0.2-14.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090355004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090355009" version="502" comment="evolution-data-server-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090354003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090358002" version="502" comment="evolution is earlier than 0:1.4.5-25.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090355002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090358003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090358004" version="502" comment="evolution-devel is earlier than 0:1.4.5-25.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090355003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090358003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361002" version="502" comment="NetworkManager is earlier than 1:0.7.0-4.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090361003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361003" version="502" comment="NetworkManager is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361004" version="502" comment="NetworkManager-glib-devel is earlier than 1:0.7.0-4.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090361003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361005" version="502" comment="NetworkManager-glib-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361006" version="502" comment="NetworkManager-devel is earlier than 1:0.7.0-4.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090361003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361007" version="502" comment="NetworkManager-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361008" version="502" comment="NetworkManager-glib is earlier than 1:0.7.0-4.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090361003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361009" version="502" comment="NetworkManager-glib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361010" version="502" comment="NetworkManager-gnome is earlier than 1:0.7.0-4.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090361003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090361011" version="502" comment="NetworkManager-gnome is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090362002" version="502" comment="NetworkManager is earlier than 0:0.3.1-5.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090362003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090362003" version="502" comment="NetworkManager is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090362004" version="502" comment="NetworkManager-gnome is earlier than 0:0.3.1-5.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090362003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090362005" version="502" comment="NetworkManager-gnome is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090361006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369002" version="502" comment="java-1.6.0-ibm is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369004" version="502" comment="java-1.6.0-ibm-jdbc is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369006" version="502" comment="java-1.6.0-ibm-devel is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369008" version="502" comment="java-1.6.0-ibm-src is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369010" version="502" comment="java-1.6.0-ibm-plugin is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369012" version="502" comment="java-1.6.0-ibm-javacomm is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369014" version="502" comment="java-1.6.0-ibm-demo is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090369016" version="502" comment="java-1.6.0-ibm-accessibility is earlier than 1:1.6.0.4-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090015005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090369004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373002" version="502" comment="systemtap is earlier than 0:0.7.2-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373003" version="502" comment="systemtap is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373004" version="502" comment="systemtap-client is earlier than 0:0.7.2-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373005" version="502" comment="systemtap-client is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373006" version="502" comment="systemtap-runtime is earlier than 0:0.7.2-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373007" version="502" comment="systemtap-runtime is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373008" version="502" comment="systemtap-testsuite is earlier than 0:0.7.2-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373009" version="502" comment="systemtap-testsuite is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373010" version="502" comment="systemtap-server is earlier than 0:0.7.2-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373011" version="502" comment="systemtap-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373013" version="502" comment="systemtap is earlier than 0:0.6.2-2.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373014" version="502" comment="systemtap is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373015" version="502" comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373016" version="502" comment="systemtap-runtime is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373017" version="502" comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090373006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090373018" version="502" comment="systemtap-testsuite is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090373005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090376002" version="502" comment="acroread is earlier than 0:8.1.4-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090376004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090376003" version="502" comment="acroread is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090376004" version="502" comment="acroread-plugin is earlier than 0:8.1.4-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090376004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090376005" version="502" comment="acroread-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377002" version="502" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090377003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377003" version="502" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377004" version="502" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090377003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377005" version="502" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377006" version="502" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090377003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377007" version="502" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377008" version="502" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090377003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377009" version="502" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377010" version="502" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090377003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090377011" version="502" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090377006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392002" version="502" comment="java-1.6.0-sun is earlier than 1:1.6.0.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090392004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392003" version="502" comment="java-1.6.0-sun is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392004" version="502" comment="java-1.6.0-sun-src is earlier than 1:1.6.0.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090392004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392005" version="502" comment="java-1.6.0-sun-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392006" version="502" comment="java-1.6.0-sun-jdbc is earlier than 1:1.6.0.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090392004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392007" version="502" comment="java-1.6.0-sun-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392008" version="502" comment="java-1.6.0-sun-devel is earlier than 1:1.6.0.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090392004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392009" version="502" comment="java-1.6.0-sun-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392010" version="502" comment="java-1.6.0-sun-demo is earlier than 1:1.6.0.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090392004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392011" version="502" comment="java-1.6.0-sun-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392012" version="502" comment="java-1.6.0-sun-plugin is earlier than 1:1.6.0.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090392004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090392013" version="502" comment="java-1.6.0-sun-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090392007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394002" version="502" comment="java-1.5.0-sun is earlier than 0:1.5.0.18-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090394004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394003" version="502" comment="java-1.5.0-sun is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394004" version="502" comment="java-1.5.0-sun-devel is earlier than 0:1.5.0.18-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090394004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394005" version="502" comment="java-1.5.0-sun-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394006" version="502" comment="java-1.5.0-sun-demo is earlier than 0:1.5.0.18-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090394004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394007" version="502" comment="java-1.5.0-sun-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394008" version="502" comment="java-1.5.0-sun-jdbc is earlier than 0:1.5.0.18-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090394004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394009" version="502" comment="java-1.5.0-sun-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394010" version="502" comment="java-1.5.0-sun-src is earlier than 0:1.5.0.18-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090394004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394011" version="502" comment="java-1.5.0-sun-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394012" version="502" comment="java-1.5.0-sun-plugin is earlier than 0:1.5.0.18-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090394004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090394013" version="502" comment="java-1.5.0-sun-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090394007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090397002" version="502" comment="xulrunner is earlier than 0:1.9.0.7-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090397004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090397004" version="502" comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090397004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090397006" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090397004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090397009" version="502" comment="firefox is earlier than 0:3.0.7-3.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090397006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398004" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398006" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398008" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398010" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398012" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398014" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398016" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398018" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398020" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.36.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398023" version="502" comment="seamonkey is earlier than 0:1.0.9-40.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398024" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-40.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398025" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-40.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398026" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-40.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398027" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-40.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090398028" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-40.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090398005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090402002" version="502" comment="openswan is earlier than 0:2.6.14-1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090402002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090402003" version="502" comment="openswan is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090402002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090402004" version="502" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090402003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090402003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090402005" version="502" comment="openswan-doc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090402003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408002" version="502" comment="krb5 is earlier than 0:1.6.1-31.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408003" version="502" comment="krb5 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408004" version="502" comment="krb5-workstation is earlier than 0:1.6.1-31.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408005" version="502" comment="krb5-workstation is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408006" version="502" comment="krb5-devel is earlier than 0:1.6.1-31.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408007" version="502" comment="krb5-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408008" version="502" comment="krb5-libs is earlier than 0:1.6.1-31.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408009" version="502" comment="krb5-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408010" version="502" comment="krb5-server is earlier than 0:1.6.1-31.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090408003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090408011" version="502" comment="krb5-server is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409002" version="502" comment="krb5 is earlier than 0:1.3.4-60.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090409003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409003" version="502" comment="krb5 is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409004" version="502" comment="krb5-devel is earlier than 0:1.3.4-60.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090409003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409005" version="502" comment="krb5-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409006" version="502" comment="krb5-libs is earlier than 0:1.3.4-60.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090409003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409007" version="502" comment="krb5-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409008" version="502" comment="krb5-workstation is earlier than 0:1.3.4-60.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090409003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409009" version="502" comment="krb5-workstation is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409010" version="502" comment="krb5-server is earlier than 0:1.3.4-60.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090409003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090409011" version="502" comment="krb5-server is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090410002" version="502" comment="krb5 is earlier than 0:1.2.7-70" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090410003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090410004" version="502" comment="krb5-workstation is earlier than 0:1.2.7-70" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090410003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090410006" version="502" comment="krb5-libs is earlier than 0:1.2.7-70" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090410003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090410008" version="502" comment="krb5-server is earlier than 0:1.2.7-70" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090410003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090410010" version="502" comment="krb5-devel is earlier than 0:1.2.7-70" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090408004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090410003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090411002" version="502" comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090411002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090411004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090411003" version="502" comment="device-mapper-multipath is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090411002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090411004" version="502" comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090411003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090411004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090411005" version="502" comment="kpartx is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090411003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090411007" version="502" comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090411002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090411006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090411008" version="502" comment="device-mapper-multipath is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090411002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090420002" version="502" comment="ghostscript is earlier than 0:7.05-32.1.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090420004" version="502" comment="ghostscript-devel is earlier than 0:7.05-32.1.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090420003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090420006" version="502" comment="hpijs is earlier than 0:1.3-32.1.20" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090420004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090420009" version="502" comment="ghostscript is earlier than 0:7.07-33.2.el4_7.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090420006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090420010" version="502" comment="ghostscript-devel is earlier than 0:7.07-33.2.el4_7.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090420006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090420011" version="502" comment="ghostscript-gtk is earlier than 0:7.07-33.2.el4_7.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090420006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090421002" version="502" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090421003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090421004" version="502" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090421003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090421006" version="502" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090345003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090421003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090427002" version="502" comment="udev is earlier than 0:095-14.20.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090427002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090427003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090427003" version="502" comment="udev is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090427002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090427004" version="502" comment="libvolume_id-devel is earlier than 0:095-14.20.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090427003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090427003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090427005" version="502" comment="libvolume_id-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090427003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090427006" version="502" comment="libvolume_id is earlier than 0:095-14.20.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090427004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090427003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090427007" version="502" comment="libvolume_id is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090427004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090428002" version="502" comment="cups is earlier than 1:1.1.17-13.3.58" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090428003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090428004" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.58" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090428003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090428006" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.58" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090428003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429002" version="502" comment="cups is earlier than 1:1.3.7-8.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429003" version="502" comment="cups is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429004" version="502" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429005" version="502" comment="cups-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429006" version="502" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090429004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429007" version="502" comment="cups-lpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090429004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429008" version="502" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429009" version="502" comment="cups-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429011" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429013" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090429015" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090429006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090430002" version="502" comment="xpdf is earlier than 1:2.02-14.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090430002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090430003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090430003" version="502" comment="xpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090430002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090430005" version="502" comment="xpdf is earlier than 1:3.00-20.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090430002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090430005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431002" version="502" comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090431004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431003" version="502" comment="kdegraphics is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431004" version="502" comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090431004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431005" version="502" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431007" version="502" comment="kdegraphics is earlier than 7:3.3.1-13.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090431006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431008" version="502" comment="kdegraphics is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431009" version="502" comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090431006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090431010" version="502" comment="kdegraphics-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090436002" version="503" comment="xulrunner is earlier than 0:1.9.0.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090436004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090436004" version="503" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090436004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090436006" version="503" comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090436004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090436008" version="503" comment="firefox is earlier than 0:3.0.9-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090436005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090436011" version="503" comment="firefox is earlier than 0:3.0.9-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090436007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437002" version="503" comment="seamonkey is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437004" version="503" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437006" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437008" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437010" version="503" comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437012" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437014" version="503" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437016" version="503" comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437018" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437020" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437023" version="503" comment="seamonkey is earlier than 0:1.0.9-41.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437024" version="503" comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437025" version="503" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437026" version="503" comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437027" version="503" comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090437028" version="503" comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090437005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090444002" version="502" comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090444002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090444003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090444003" version="502" comment="giflib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090444002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090444004" version="502" comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090444003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090444003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090444005" version="502" comment="giflib-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090444003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090444006" version="502" comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090444004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090444003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090444007" version="502" comment="giflib-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090444004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445002" version="502" comment="java-1.4.2-ibm is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445003" version="502" comment="java-1.4.2-ibm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445004" version="502" comment="java-1.4.2-ibm-devel is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445005" version="502" comment="java-1.4.2-ibm-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445006" version="502" comment="java-1.4.2-ibm-jdbc is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445007" version="502" comment="java-1.4.2-ibm-jdbc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445008" version="502" comment="java-1.4.2-ibm-javacomm is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445009" version="502" comment="java-1.4.2-ibm-javacomm is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445010" version="502" comment="java-1.4.2-ibm-demo is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445011" version="502" comment="java-1.4.2-ibm-demo is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445012" version="502" comment="java-1.4.2-ibm-src is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445013" version="502" comment="java-1.4.2-ibm-src is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445014" version="502" comment="java-1.4.2-ibm-plugin is earlier than 0:1.4.2.13-1jpp.1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090445004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090445015" version="502" comment="java-1.4.2-ibm-plugin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090445008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090449002" version="502" comment="xulrunner is earlier than 0:1.9.0.10-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090449004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090449004" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.10-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090449004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090449006" version="502" comment="xulrunner-devel is earlier than 0:1.9.0.10-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090449004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090449008" version="502" comment="firefox is earlier than 0:3.0.10-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090449005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090449011" version="502" comment="firefox is earlier than 0:3.0.10-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090449007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457002" version="502" comment="libwmf is earlier than 0:0.2.8.4-10.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090457004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457003" version="502" comment="libwmf is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457004" version="502" comment="libwmf-devel is earlier than 0:0.2.8.4-10.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090457004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457005" version="502" comment="libwmf-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457007" version="502" comment="libwmf is earlier than 0:0.2.8.3-5.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090457006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457008" version="502" comment="libwmf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457009" version="502" comment="libwmf-devel is earlier than 0:0.2.8.3-5.8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090457006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090457010" version="502" comment="libwmf-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090457003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090458002" version="502" comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090458002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090458003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090458003" version="502" comment="gpdf is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090458002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459002" version="502" comment="kernel is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459004" version="502" comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459006" version="502" comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459008" version="502" comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459010" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459012" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459014" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459016" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090459022" version="502" comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090459003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473002" version="502" comment="kernel is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473004" version="502" comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473006" version="502" comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473008" version="502" comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473010" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473012" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473014" version="502" comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473016" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473018" version="502" comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473020" version="502" comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473022" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090473024" version="502" comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090473003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090474002" version="502" comment="acpid is earlier than 0:1.0.4-7.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090474004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090474003" version="502" comment="acpid is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090474005" version="502" comment="acpid is earlier than 0:1.0.2-4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090474006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090474006" version="502" comment="acpid is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090474008" version="502" comment="acpid is earlier than 0:1.0.3-2.el4_7.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090474002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090474008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476002" version="502" comment="pango is earlier than 0:1.14.9-5.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476003" version="502" comment="pango is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476004" version="502" comment="pango-devel is earlier than 0:1.14.9-5.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476005" version="502" comment="pango-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476007" version="502" comment="pango is earlier than 0:1.2.5-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476008" version="502" comment="pango is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476009" version="502" comment="pango-devel is earlier than 0:1.2.5-8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476010" version="502" comment="pango-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476012" version="502" comment="pango is earlier than 0:1.6.0-14.4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476013" version="502" comment="pango-devel is earlier than 0:1.6.0-14.4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476014" version="502" comment="evolution28-pango is earlier than 0:1.14.9-11.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476015" version="502" comment="evolution28-pango is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476016" version="502" comment="evolution28-pango-devel is earlier than 0:1.14.9-11.el4_7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090476009" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090476017" version="502" comment="evolution28-pango-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090476005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090478002" version="502" comment="acroread is earlier than 0:8.1.5-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090478004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090478004" version="502" comment="acroread-plugin is earlier than 0:8.1.5-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090478004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090479002" version="502" comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090479002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090479003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090479003" version="502" comment="perl-DBD-Pg is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090479002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090480002" version="502" comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090480002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090480003" version="502" comment="poppler is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090480002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090480004" version="502" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090480003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090480005" version="502" comment="poppler-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090480003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090480006" version="502" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090480004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090480003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090480007" version="502" comment="poppler-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090480004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090955002" version="502" comment="nfs-utils is earlier than 0:1.0.6-93.EL4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090955002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090955003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090955003" version="502" comment="nfs-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090955002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090981002" version="502" comment="util-linux is earlier than 0:2.12a-24.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090981002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090981003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20090981003" version="502" comment="util-linux is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090981002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024002" version="502" comment="kernel is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024004" version="502" comment="kernel-devel is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024006" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024008" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024010" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024012" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024014" version="502" comment="kernel-xenU is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024016" version="502" comment="kernel-smp is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024018" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024020" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091024022" version="502" comment="kernel-doc is earlier than 0:2.6.9-89.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091024003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091036002" version="502" comment="ipsec-tools is earlier than 0:0.6.5-13.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091036002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091036003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091036003" version="502" comment="ipsec-tools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091036002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038002" version="502" comment="java-1.5.0-ibm is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038004" version="502" comment="java-1.5.0-ibm-jdbc is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038006" version="502" comment="java-1.5.0-ibm-devel is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038008" version="502" comment="java-1.5.0-ibm-accessibility is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038010" version="502" comment="java-1.5.0-ibm-demo is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038012" version="502" comment="java-1.5.0-ibm-javacomm is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038014" version="502" comment="java-1.5.0-ibm-plugin is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091038016" version="502" comment="java-1.5.0-ibm-src is earlier than 1:1.5.0.9-1jpp.3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090016008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091038004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091039002" version="502" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090046002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091039003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091040002" version="503" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090046002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091040003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091059002" version="503" comment="pidgin is earlier than 0:1.5.1-3.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091059003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091059003" version="503" comment="pidgin is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060002" version="503" comment="pidgin is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060003" version="503" comment="pidgin is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060004" version="503" comment="libpurple-devel is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060005" version="503" comment="libpurple-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060006" version="503" comment="finch-devel is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060007" version="503" comment="finch-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060008" version="503" comment="libpurple is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060009" version="503" comment="libpurple is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060010" version="503" comment="libpurple-perl is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060011" version="503" comment="libpurple-perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060012" version="503" comment="pidgin-perl is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060013" version="503" comment="pidgin-perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060014" version="503" comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060015" version="503" comment="libpurple-tcl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060016" version="503" comment="finch is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060017" version="503" comment="finch is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060018" version="503" comment="pidgin-devel is earlier than 0:2.5.5-3.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060019" version="503" comment="pidgin-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060021" version="503" comment="pidgin is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060023" version="503" comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060024" version="503" comment="libpurple-tcl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060025" version="503" comment="libpurple-devel is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060026" version="503" comment="libpurple-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060027" version="503" comment="pidgin-perl is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060028" version="503" comment="pidgin-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060029" version="503" comment="libpurple is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060030" version="503" comment="libpurple is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060031" version="503" comment="finch is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060032" version="503" comment="finch is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060033" version="503" comment="finch-devel is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060034" version="503" comment="finch-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060035" version="503" comment="pidgin-devel is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060036" version="503" comment="pidgin-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060037" version="503" comment="libpurple-perl is earlier than 0:2.5.5-2.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091060006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091060038" version="503" comment="libpurple-perl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091061002" version="503" comment="freetype is earlier than 0:2.2.1-21.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091061003" version="503" comment="freetype is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091061004" version="503" comment="freetype-devel is earlier than 0:2.2.1-21.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091061005" version="503" comment="freetype-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091061006" version="503" comment="freetype-demos is earlier than 0:2.2.1-21.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091061003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091061007" version="503" comment="freetype-demos is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090329003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091066002" version="502" comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091066004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091066005" version="502" comment="squirrelmail is earlier than 0:1.4.8-13.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091066006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091066008" version="502" comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090010002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091066008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075002" version="502" comment="httpd is earlier than 0:2.2.3-22.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091075003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075003" version="502" comment="httpd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075004" version="502" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091075003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075005" version="502" comment="httpd-manual is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075006" version="502" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091075003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075007" version="502" comment="httpd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075008" version="502" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091075003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091075009" version="502" comment="mod_ssl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091082002" version="502" comment="cups is earlier than 1:1.3.7-8.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091082004" version="502" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091082006" version="502" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091082008" version="502" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090429004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091082003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091083002" version="502" comment="cups is earlier than 1:1.1.17-13.3.62" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091083003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091083004" version="502" comment="cups-libs is earlier than 1:1.1.17-13.3.62" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091083003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091083006" version="502" comment="cups-devel is earlier than 1:1.1.17-13.3.62" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091083003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091083009" version="502" comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091083005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091083010" version="502" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091083005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091083011" version="502" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090308003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091083005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091095002" version="502" comment="firefox is earlier than 0:3.0.11-2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091095004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091095004" version="502" comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091095005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091095006" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091095005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091095008" version="502" comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091095005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091095011" version="502" comment="firefox is earlier than 0:3.0.11-4.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091095007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096004" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096006" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096008" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096010" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096012" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096014" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096016" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096018" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096020" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096023" version="502" comment="seamonkey is earlier than 0:1.0.9-43.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096024" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096025" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096026" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096027" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091096028" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091096005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091100002" version="502" comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091100004" version="502" comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091100004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091100007" version="502" comment="wireshark is earlier than 0:1.0.8-EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091100006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091100009" version="502" comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091100006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091100012" version="502" comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091100008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091100013" version="502" comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090313003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091100008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091101002" version="502" comment="cscope is earlier than 0:15.5-16.RHEL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091101002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091101003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091101003" version="502" comment="cscope is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091101002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091101005" version="502" comment="cscope is earlier than 0:15.5-10.RHEL4.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091101002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091101005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091102002" version="502" comment="cscope is earlier than 0:15.5-15.1.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091101002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091102003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091102003" version="502" comment="cscope is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091101002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106002" version="502" comment="kernel is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106004" version="502" comment="kernel-headers is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106006" version="502" comment="kernel-devel is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106008" version="502" comment="kernel-xen is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106010" version="502" comment="kernel-debug is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106012" version="502" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106014" version="502" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106016" version="502" comment="kernel-kdump is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106018" version="502" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106020" version="502" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106022" version="502" comment="kernel-PAE is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090225011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091106024" version="502" comment="kernel-doc is earlier than 0:2.6.18-128.1.14.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091106003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107002" version="502" comment="apr-util is earlier than 0:1.2.7-7.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091107004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107003" version="502" comment="apr-util is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107004" version="502" comment="apr-util-devel is earlier than 0:1.2.7-7.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091107004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107005" version="502" comment="apr-util-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107006" version="502" comment="apr-util-docs is earlier than 0:1.2.7-7.el5_3.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091107004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107007" version="502" comment="apr-util-docs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107009" version="502" comment="apr-util is earlier than 0:0.9.4-22.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091107006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107010" version="502" comment="apr-util is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107011" version="502" comment="apr-util-devel is earlier than 0:0.9.4-22.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091107006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091107012" version="502" comment="apr-util-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091107003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091108002" version="502" comment="httpd is earlier than 0:2.0.46-73.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091108003" version="502" comment="httpd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091108004" version="502" comment="httpd-devel is earlier than 0:2.0.46-73.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091108005" version="502" comment="httpd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091108006" version="502" comment="mod_ssl is earlier than 0:2.0.46-73.ent" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091108003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091108007" version="502" comment="mod_ssl is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091109002" version="502" comment="acroread is earlier than 0:8.1.6-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091109004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091109004" version="502" comment="acroread-plugin is earlier than 0:8.1.6-2.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090376003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091109004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116002" version="502" comment="cyrus-imapd is earlier than 0:2.3.7-2.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116003" version="502" comment="cyrus-imapd is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116004" version="502" comment="cyrus-imapd-utils is earlier than 0:2.3.7-2.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116005" version="502" comment="cyrus-imapd-utils is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116006" version="502" comment="cyrus-imapd-devel is earlier than 0:2.3.7-2.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116007" version="502" comment="cyrus-imapd-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116008" version="502" comment="cyrus-imapd-perl is earlier than 0:2.3.7-2.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116009" version="502" comment="cyrus-imapd-perl is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116011" version="502" comment="cyrus-imapd is earlier than 0:2.2.12-10.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116012" version="502" comment="cyrus-imapd is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116013" version="502" comment="cyrus-imapd-devel is earlier than 0:2.2.12-10.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116014" version="502" comment="cyrus-imapd-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116015" version="502" comment="cyrus-imapd-murder is earlier than 0:2.2.12-10.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116016" version="502" comment="cyrus-imapd-murder is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116017" version="502" comment="perl-Cyrus is earlier than 0:2.2.12-10.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116018" version="502" comment="perl-Cyrus is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116019" version="502" comment="cyrus-imapd-utils is earlier than 0:2.2.12-10.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116020" version="502" comment="cyrus-imapd-utils is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116021" version="502" comment="cyrus-imapd-nntp is earlier than 0:2.2.12-10.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091116006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091116022" version="502" comment="cyrus-imapd-nntp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091116008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091122002" version="502" comment="icu is earlier than 0:3.6-5.11.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091122004" version="502" comment="libicu-devel is earlier than 0:3.6-5.11.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091122006" version="502" comment="libicu-doc is earlier than 0:3.6-5.11.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091122008" version="502" comment="libicu is earlier than 0:3.6-5.11.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090296004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091122003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091123002" version="502" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090271002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091123003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091123004" version="502" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090271003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091123003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091124002" version="502" comment="net-snmp is earlier than 0:5.0.9-2.30E.28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091124003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091124004" version="502" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091124003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091124006" version="502" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091124003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091124008" version="502" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091124003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091124010" version="502" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.28" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090295004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091124003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091125002" version="503" comment="thunderbird is earlier than 0:1.5.0.12-23.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091125003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091126002" version="502" comment="thunderbird is earlier than 0:2.0.0.22-2.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090002002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091126003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127002" version="502" comment="kdelibs is earlier than 6:3.5.4-22.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091127004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127003" version="502" comment="kdelibs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127004" version="502" comment="kdelibs-apidocs is earlier than 6:3.5.4-22.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091127004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127005" version="502" comment="kdelibs-apidocs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127006" version="502" comment="kdelibs-devel is earlier than 6:3.5.4-22.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091127004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127007" version="502" comment="kdelibs-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127009" version="502" comment="kdelibs is earlier than 6:3.3.1-14.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091127006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127010" version="502" comment="kdelibs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127011" version="502" comment="kdelibs-devel is earlier than 6:3.3.1-14.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091127006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091127012" version="502" comment="kdelibs-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091128002" version="502" comment="kdelibs is earlier than 6:3.1.3-6.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091128003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091128004" version="502" comment="kdelibs-devel is earlier than 6:3.1.3-6.13" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091127004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091128003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091130002" version="502" comment="kdegraphics is earlier than 7:3.5.4-13.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091130003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091130004" version="502" comment="kdegraphics-devel is earlier than 7:3.5.4-13.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090431003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091130003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132002" version="502" comment="kernel is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132004" version="502" comment="kernel-devel is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132006" version="502" comment="kernel-largesmp is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132008" version="502" comment="kernel-smp-devel is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132010" version="502" comment="kernel-xenU-devel is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132012" version="502" comment="kernel-xenU is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132014" version="502" comment="kernel-smp is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132016" version="502" comment="kernel-largesmp-devel is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132018" version="502" comment="kernel-hugemem-devel is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132020" version="502" comment="kernel-hugemem is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091132022" version="502" comment="kernel-doc is earlier than 0:2.6.9-89.0.3.EL" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090014012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091132003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134004" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134006" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134008" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134010" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134012" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134014" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134016" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134018" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134020" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.39.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134023" version="502" comment="seamonkey is earlier than 0:1.0.9-44.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134024" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-44.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134025" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-44.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134026" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-44.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134027" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-44.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091134028" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-44.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091134005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091136002" version="502" comment="dhcp is earlier than 7:3.0.1-65.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091136003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091136003" version="502" comment="dhcp is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091136004" version="502" comment="dhcp-devel is earlier than 7:3.0.1-65.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091136003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091136005" version="502" comment="dhcp-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091136006" version="502" comment="dhclient is earlier than 7:3.0.1-65.el4_8.1" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091136003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091136007" version="502" comment="dhclient is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091138002" version="502" comment="openswan is earlier than 0:2.6.14-1.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090402002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091138004" version="502" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090402003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091138003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139002" version="502" comment="pidgin is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139004" version="502" comment="libpurple-tcl is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139006" version="502" comment="libpurple-devel is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139008" version="502" comment="finch-devel is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139010" version="502" comment="pidgin-perl is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139012" version="502" comment="libpurple is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139014" version="502" comment="finch is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139016" version="502" comment="pidgin-devel is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139018" version="502" comment="libpurple-perl is earlier than 0:2.5.8-1.el5" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139021" version="502" comment="pidgin is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091059002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139023" version="502" comment="libpurple is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139025" version="502" comment="finch-devel is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139027" version="502" comment="libpurple-devel is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139029" version="502" comment="libpurple-tcl is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139031" version="502" comment="libpurple-perl is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139033" version="502" comment="pidgin-perl is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139035" version="502" comment="finch is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091139037" version="502" comment="pidgin-devel is earlier than 0:2.5.8-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091060010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091139006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140002" version="503" comment="ruby is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140003" version="503" comment="ruby is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140004" version="503" comment="ruby-docs is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140005" version="503" comment="ruby-docs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140006" version="503" comment="ruby-irb is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140007" version="503" comment="ruby-irb is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140008" version="503" comment="ruby-ri is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140009" version="503" comment="ruby-ri is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140010" version="503" comment="ruby-mode is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140011" version="503" comment="ruby-mode is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140012" version="503" comment="ruby-libs is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140013" version="503" comment="ruby-libs is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140014" version="503" comment="ruby-rdoc is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140015" version="503" comment="ruby-rdoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140016" version="503" comment="ruby-devel is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140017" version="503" comment="ruby-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140018" version="503" comment="ruby-tcltk is earlier than 0:1.8.5-5.el5_3.7" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140019" version="503" comment="ruby-tcltk is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140021" version="503" comment="ruby is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140022" version="503" comment="ruby is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140023" version="503" comment="ruby-mode is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140024" version="503" comment="ruby-mode is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140025" version="503" comment="ruby-docs is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140026" version="503" comment="ruby-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140027" version="503" comment="ruby-devel is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140028" version="503" comment="ruby-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140029" version="503" comment="ruby-libs is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140030" version="503" comment="ruby-libs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140031" version="503" comment="irb is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140032" version="503" comment="irb is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140033" version="503" comment="ruby-tcltk is earlier than 0:1.8.1-7.el4_8.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091140006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091140034" version="503" comment="ruby-tcltk is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091140010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091148002" version="502" comment="httpd is earlier than 0:2.2.3-22.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091148003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091148004" version="502" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091148003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091148006" version="502" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091148003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091148008" version="502" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091075004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091148003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091154002" version="503" comment="dhcp is earlier than 7:3.0.1-10.2_EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091154004" version="503" comment="dhcp-devel is earlier than 7:3.0.1-10.2_EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091154006" version="503" comment="dhclient is earlier than 7:3.0.1-10.2_EL3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091136004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091154003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159002" version="502" comment="libtiff is earlier than 0:3.8.2-7.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091159004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159003" version="502" comment="libtiff is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159004" version="502" comment="libtiff-devel is earlier than 0:3.8.2-7.el5_3.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091159004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159005" version="502" comment="libtiff-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159007" version="502" comment="libtiff is earlier than 0:3.5.7-33.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091159006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159008" version="502" comment="libtiff is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159009" version="502" comment="libtiff-devel is earlier than 0:3.5.7-33.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091159006" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159010" version="502" comment="libtiff-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159012" version="502" comment="libtiff is earlier than 0:3.6.1-12.el4_8.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091159008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091159013" version="502" comment="libtiff-devel is earlier than 0:3.6.1-12.el4_8.4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091159003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091159008" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091162002" version="502" comment="xulrunner is earlier than 0:1.9.0.12-1.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091162004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091162004" version="502" comment="xulrunner-devel is earlier than 0:1.9.0.12-1.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091162004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091162006" version="502" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.12-1.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091162004" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091162008" version="502" comment="firefox is earlier than 0:3.0.12-1.el5_3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091162005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091162011" version="502" comment="firefox is earlier than 0:3.0.12-1.el4" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090256005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091162007" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163002" version="502" comment="seamonkey is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163004" version="502" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163006" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163008" version="502" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163010" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163012" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163014" version="502" comment="seamonkey-nss is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163016" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163018" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163020" version="502" comment="seamonkey-nspr is earlier than 0:1.0.9-0.40.el3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163023" version="502" comment="seamonkey is earlier than 0:1.0.9-45.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163024" version="502" comment="seamonkey-chat is earlier than 0:1.0.9-45.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163025" version="502" comment="seamonkey-mail is earlier than 0:1.0.9-45.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163026" version="502" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-45.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163027" version="502" comment="seamonkey-js-debugger is earlier than 0:1.0.9-45.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091163028" version="502" comment="seamonkey-devel is earlier than 0:1.0.9-45.el4_8" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090257006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091163005" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164002" version="502" comment="tomcat5 is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164003" version="502" comment="tomcat5 is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164004" version="502" comment="tomcat5-servlet-2.4-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164005" version="502" comment="tomcat5-servlet-2.4-api is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164006" version="502" comment="tomcat5-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164007" version="502" comment="tomcat5-webapps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164008" version="502" comment="tomcat5-servlet-2.4-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164009" version="502" comment="tomcat5-servlet-2.4-api-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164010" version="502" comment="tomcat5-jasper-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164011" version="502" comment="tomcat5-jasper-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164006" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164012" version="502" comment="tomcat5-server-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164013" version="502" comment="tomcat5-server-lib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164007" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164014" version="502" comment="tomcat5-admin-webapps is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164015" version="502" comment="tomcat5-admin-webapps is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164008" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164016" version="502" comment="tomcat5-jsp-2.0-api-javadoc is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164017" version="502" comment="tomcat5-jsp-2.0-api-javadoc is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164009" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164018" version="502" comment="tomcat5-jasper is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164019" version="502" comment="tomcat5-jasper is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164010" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164020" version="502" comment="tomcat5-common-lib is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164021" version="502" comment="tomcat5-common-lib is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164011" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164022" version="502" comment="tomcat5-jsp-2.0-api is earlier than 0:5.5.23-0jpp.7.el5_3.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091164003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091164023" version="502" comment="tomcat5-jsp-2.0-api is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091164012" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176002" version="502" comment="python is earlier than 0:2.4.3-24.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176003" version="502" comment="python is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176004" version="502" comment="python-devel is earlier than 0:2.4.3-24.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176005" version="502" comment="python-devel is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176006" version="502" comment="tkinter is earlier than 0:2.4.3-24.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176007" version="502" comment="tkinter is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176008" version="502" comment="python-tools is earlier than 0:2.4.3-24.el5_3.6" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091176003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091176009" version="502" comment="python-tools is signed with Red Hat redhatrelease key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002002" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177002" version="502" comment="python is earlier than 0:2.3.4-14.7.el4_8.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091177003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177003" version="502" comment="python is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177004" version="502" comment="python-docs is earlier than 0:2.3.4-14.7.el4_8.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091177003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177005" version="502" comment="python-docs is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177006" version="502" comment="python-devel is earlier than 0:2.3.4-14.7.el4_8.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091177003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177007" version="502" comment="python-devel is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177008" version="502" comment="tkinter is earlier than 0:2.3.4-14.7.el4_8.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091177003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177009" version="502" comment="tkinter is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177010" version="502" comment="python-tools is earlier than 0:2.3.4-14.7.el4_8.2" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091177003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091177011" version="502" comment="python-tools is signed with Red Hat master key" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20090002001" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091178002" version="503" comment="python is earlier than 0:2.2.3-6.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091178003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091178004" version="503" comment="tkinter is earlier than 0:2.2.3-6.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176004" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091178003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091178006" version="503" comment="python-tools is earlier than 0:2.2.3-6.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176005" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091178003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091178008" version="503" comment="python-devel is earlier than 0:2.2.3-6.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091176003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091178003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091178010" version="503" comment="python-docs is earlier than 0:2.2.3-6.11" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20091177003" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091178003" />
</rpminfo_test>
<rpminfo_test xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" id="oval:com.redhat.rhsa:tst:20091179002" version="503" comment="bind is earlier than 30:9.3.4-10.P1.el5_3.3" check="at least one">
  <object object_ref="oval:com.redhat.rhsa:obj:20090020002" />
  <state state_ref="oval:com.redhat.rhsa:ste:20091179003" />
</rpminfo_test>
<rpminfo_test xmlns
