<?xml version="1.0" encoding="UTF-8"?>

<oval_definitions xmlns="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:oval="http://oval.mitre.org/XMLSchema/oval-common-5" xmlns:oval-def="http://oval.mitre.org/XMLSchema/oval-definitions-5" xmlns:unix-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#unix" xmlns:red-def="http://oval.mitre.org/XMLSchema/oval-definitions-5#linux" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#linux linux-definitions-schema.xsd">
  <generator>
    <oval:product_name>Red Hat OVAL Patch Definition Merger</oval:product_name>
    <oval:product_version>2</oval:product_version>
    <oval:schema_version>5.3</oval:schema_version>
    <oval:timestamp>2009-11-30T10:42:35
</oval:timestamp>
  </generator>
<definitions>
<definition id="oval:com.redhat.rhsa:def:20090003" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0003: xen security and bug fix update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0003-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0003.html" />
    <description>The xen packages contain the Xen tools and management daemons needed to
manage virtual machines running on Red Hat Enterprise Linux.

Xen was found to allow unprivileged DomU domains to overwrite xenstore
values which should only be changeable by the privileged Dom0 domain. An
attacker controlling a DomU domain could, potentially, use this flaw to
kill arbitrary processes in Dom0 or trick a Dom0 user into accessing the
text console of a different domain running on the same host. This update
makes certain parts of the xenstore tree read-only to the unprivileged DomU
domains. (CVE-2008-4405)

It was discovered that the qemu-dm.debug script created a temporary file in
/tmp in an insecure way. A local attacker in Dom0 could, potentially, use
this flaw to overwrite arbitrary files via a symlink attack. Note: This
script is not needed in production deployments and therefore was removed
and is not shipped with updated xen packages. (CVE-2008-4993)

This update also fixes the following bug:

* xen calculates its running time by adding the hypervisor's up-time to the
hypervisor's boot-time record. In live migrations of para-virtualized
guests, however, the guest would over-write the new hypervisor's boot-time
record with the boot-time of the previous hypervisor. This caused
time-dependent processes on the guests to fail (for example, crond would
fail to start cron jobs). With this update, the new hypervisor's boot-time
record is no longer over-written during live migrations.

All xen users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The Xen host must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4405">CVE-2008-4405</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4993">CVE-2008-4993</cve>
                <bugzilla href="http://bugzilla.redhat.com/470795" id="470795">CVE-2008-4993 xen: insecure temporary file use in qemu-dm.debug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464455" id="464455">timer stops running after live migrate or dom0 reboot &amp; save/restore of a Xen guest</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464817" id="464817">CVE-2008-4405 xen: Multiple unsafe uses of guest-writable data from xenstore</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003002" comment="xen is earlier than 0:3.0.3-64.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003003" comment="xen is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003006" comment="xen-libs is earlier than 0:3.0.3-64.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003007" comment="xen-libs is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003004" comment="xen-devel is earlier than 0:3.0.3-64.el5_2.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090003005" comment="xen-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090004" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0004: openssl security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0004-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0004.html" />
    <description>OpenSSL is a toolkit that implements Secure Sockets Layer (SSL v2/v3) and
Transport Layer Security (TLS v1) protocols as well as a full-strength,
general purpose, cryptography library.

The Google security team discovered a flaw in the way OpenSSL checked the
verification of certificates. An attacker in control of a malicious server,
or able to effect a "man in the middle" attack, could present a malformed
SSL/TLS signature from a certificate chain to a vulnerable client and
bypass validation. (CVE-2008-5077)

All OpenSSL users should upgrade to these updated packages, which contain
backported patches to resolve these issues. For the update to take effect,
all running OpenSSL client applications must be restarted, or the system
rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5077">CVE-2008-5077</cve>
                <bugzilla href="http://bugzilla.redhat.com/476671" id="476671">CVE-2008-5077 OpenSSL Incorrect checks for malformed signatures</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004002" comment="openssl097a is earlier than 0:0.9.7a-9.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004003" comment="openssl097a is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004004" comment="openssl is earlier than 0:0.9.8b-10.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004005" comment="openssl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004008" comment="openssl-perl is earlier than 0:0.9.8b-10.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004009" comment="openssl-perl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004006" comment="openssl-devel is earlier than 0:0.9.8b-10.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004007" comment="openssl-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004011" comment="openssl is earlier than 0:0.9.7a-33.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004012" comment="openssl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004013" comment="openssl-perl is earlier than 0:0.9.7a-33.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004014" comment="openssl-perl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004015" comment="openssl-devel is earlier than 0:0.9.7a-33.25" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004016" comment="openssl-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004017" comment="openssl096b is earlier than 0:0.9.6b-16.49" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004018" comment="openssl096b is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004022" comment="openssl is earlier than 0:0.9.7a-43.17.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004012" comment="openssl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004021" comment="openssl-perl is earlier than 0:0.9.7a-43.17.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004014" comment="openssl-perl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004020" comment="openssl-devel is earlier than 0:0.9.7a-43.17.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004016" comment="openssl-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004023" comment="openssl096b is earlier than 0:0.9.6b-22.46.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090004018" comment="openssl096b is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090005" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0005: gnome-vfs, gnome-vfs2 security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0005-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0005.html" />
    <description>GNOME VFS is the GNOME virtual file system. It provides a modular
architecture and ships with several modules that implement support for
various local and remote file systems as well as numerous protocols,
including HTTP, FTP, and others.

A buffer overflow flaw was discovered in the GNOME virtual file system when
handling data returned by CDDB servers. If a user connected to a malicious
CDDB server, an attacker could use this flaw to execute arbitrary code on
the victim's machine. (CVE-2005-0706)

Users of gnome-vfs and gnome-vfs2 are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. All
running GNOME sessions must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-0706">CVE-2005-0706</cve>
                <bugzilla href="http://bugzilla.redhat.com/470552" id="470552">CVE-2005-0706 grip,libcdaudio: buffer overflow caused by large amount of CDDB replies</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005002" comment="gnome-vfs2-devel is earlier than 0:2.2.5-2E.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005003" comment="gnome-vfs2-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005004" comment="gnome-vfs2 is earlier than 0:2.2.5-2E.3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005005" comment="gnome-vfs2 is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005010" comment="gnome-vfs2-devel is earlier than 0:2.8.2-8.7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005003" comment="gnome-vfs2-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005007" comment="gnome-vfs2-smb is earlier than 0:2.8.2-8.7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005008" comment="gnome-vfs2-smb is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090005009" comment="gnome-vfs2 is earlier than 0:2.8.2-8.7.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090005005" comment="gnome-vfs2 is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090008" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0008: dbus security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0008-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0008.html" />
    <description>D-Bus is a system for sending messages between applications. It is used for
the system-wide message bus service and as a per-user-login-session
messaging facility.

A denial-of-service flaw was discovered in the system for sending messages
between applications. A local user could send a message with a malformed
signature to the bus causing the bus (and, consequently, any process using
libdbus to receive messages) to abort. (CVE-2008-3834)

All users are advised to upgrade to these updated dbus packages, which
contain backported patch which resolve this issue. For the update to take
effect, all running instances of dbus-daemon and all running applications
using libdbus library must be restarted, or the system rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3834">CVE-2008-3834</cve>
                <bugzilla href="http://bugzilla.redhat.com/464674" id="464674">CVE-2008-3834 dbus denial of service</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090008006" comment="dbus-x11 is earlier than 0:1.0.0-7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090008007" comment="dbus-x11 is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090008004" comment="dbus-devel is earlier than 0:1.0.0-7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090008005" comment="dbus-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090008002" comment="dbus is earlier than 0:1.0.0-7.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090008003" comment="dbus is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090010" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0010: squirrelmail security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0010-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0010.html" />
    <description>SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.

Ivan Markovic discovered a cross-site scripting (XSS) flaw in SquirrelMail
caused by insufficient HTML mail sanitization. A remote attacker could send
a specially-crafted HTML mail or attachment that could cause a user's Web
browser to execute a malicious script in the context of the SquirrelMail
session when that email or attachment was opened by the user.
(CVE-2008-2379)

It was discovered that SquirrelMail allowed cookies over insecure
connections (ie did not restrict cookies to HTTPS connections). An attacker
who controlled the communication channel between a user and the
SquirrelMail server, or who was able to sniff the user's network
communication, could use this flaw to obtain the user's session cookie, if
a user made an HTTP request to the server. (CVE-2008-3663)

Note: After applying this update, all session cookies set for SquirrelMail
sessions started over HTTPS connections will have the "secure" flag set.
That is, browsers will only send such cookies over an HTTPS connection. If
needed, you can revert to the previous behavior by setting the
configuration option "$only_secure_cookies" to "false" in SquirrelMail's
/etc/squirrelmail/config.php configuration file.

Users of squirrelmail should upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-12" />
        <updated date="2009-01-12" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2379">CVE-2008-2379</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3663">CVE-2008-3663</cve>
                <bugzilla href="http://bugzilla.redhat.com/464183" id="464183">CVE-2008-3663 squirrelmail: session hijacking - secure flag not set for HTTPS-only cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473877" id="473877">CVE-2008-2379 squirrelmail: XSS issue caused by an insufficient html mail sanitation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010005" comment="squirrelmail is earlier than 0:1.4.8-8.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090011" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0011: lcms security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0011-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0011.html" />
    <description>Little Color Management System (LittleCMS, or simply "lcms") is a
small-footprint, speed-optimized open source color management engine.

Multiple insufficient input validation flaws were discovered in LittleCMS.
An attacker could use these flaws to create a specially-crafted image file
which could cause an application using LittleCMS to crash, or, possibly,
execute arbitrary code when opened. (CVE-2008-5316, CVE-2008-5317)

Users of lcms should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
lcms library must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5316">CVE-2008-5316</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5317">CVE-2008-5317</cve>
                <bugzilla href="http://bugzilla.redhat.com/473462" id="473462">CVE-2008-5316 lcms: insufficient input validation in ReadEmbeddedTextTag</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473463" id="473463">CVE-2008-5317 lcms: unsigned -> signed integer cast issue in cmsAllocGamma</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090011006" comment="lcms is earlier than 0:1.15-1.2.2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011007" comment="lcms is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090011002" comment="lcms-devel is earlier than 0:1.15-1.2.2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011003" comment="lcms-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090011004" comment="python-lcms is earlier than 0:1.15-1.2.2.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011005" comment="python-lcms is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090012" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0012: netpbm security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0012-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0012.html" />
    <description>The netpbm package contains a library of functions for editing and
converting between various graphics file formats, including .pbm (portable
bitmaps), .pgm (portable graymaps), .pnm (portable anymaps), .ppm (portable
pixmaps), and others.

An input validation flaw and multiple integer overflows were discovered in
the JasPer library providing support for JPEG-2000 image format and used in
the jpeg2ktopam and pamtojpeg2k converters. An attacker could create a
carefully-crafted JPEG file which could cause jpeg2ktopam to crash or,
possibly, execute arbitrary code as the user running jpeg2ktopam.
(CVE-2007-2721, CVE-2008-3520)

All users are advised to upgrade to these updated packages which contain
backported patches which resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-11" />
        <updated date="2009-02-11" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2721">CVE-2007-2721</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3520">CVE-2008-3520</cve>
                <bugzilla href="http://bugzilla.redhat.com/346501" id="346501">CVE-2007-2721 jasper crash in jpc_qcx_getcompparms</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461476" id="461476">CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012002" comment="netpbm is earlier than 0:10.35-6.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012003" comment="netpbm is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012006" comment="netpbm-devel is earlier than 0:10.35-6.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012007" comment="netpbm-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012004" comment="netpbm-progs is earlier than 0:10.35-6.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012005" comment="netpbm-progs is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012011" comment="netpbm is earlier than 0:10.25-2.1.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012012" comment="netpbm is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012013" comment="netpbm-devel is earlier than 0:10.25-2.1.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012014" comment="netpbm-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090012009" comment="netpbm-progs is earlier than 0:10.25-2.1.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090012010" comment="netpbm-progs is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090013" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0013: avahi security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0013-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0013.html" />
    <description>Avahi is an implementation of the DNS Service Discovery and Multicast DNS
specifications for Zeroconf Networking. It facilitates service discovery on
a local network. Avahi and Avahi-aware applications allow you to plug your
computer into a network and, with no configuration, view other people to
chat with, see printers to print to, and find shared files on other computers.

Hugo Dias discovered a denial of service flaw in avahi-daemon. A remote
attacker on the same local area network (LAN) could send a
specially-crafted mDNS (Multicast DNS) packet that would cause avahi-daemon
to exit unexpectedly due to a failed assertion check. (CVE-2008-5081)

All users are advised to upgrade to these updated packages, which contain a
backported patch which resolves this issue. After installing the update,
avahi-daemon will be restarted automatically.
</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-12" />
        <updated date="2009-01-12" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5081">CVE-2008-5081</cve>
                <bugzilla href="http://bugzilla.redhat.com/475964" id="475964">CVE-2008-5081 avahi: avahi-daemon DoS (application abort) via packet with source port 0</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013002" comment="avahi-compat-howl is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013003" comment="avahi-compat-howl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013020" comment="avahi-glib-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013021" comment="avahi-glib-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013006" comment="avahi is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013007" comment="avahi is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013004" comment="avahi-compat-howl-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013005" comment="avahi-compat-howl-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013016" comment="avahi-compat-libdns_sd is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013017" comment="avahi-compat-libdns_sd is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013010" comment="avahi-glib is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013011" comment="avahi-glib is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013022" comment="avahi-qt3-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013023" comment="avahi-qt3-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013018" comment="avahi-qt3 is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013019" comment="avahi-qt3 is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013014" comment="avahi-compat-libdns_sd-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013015" comment="avahi-compat-libdns_sd-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013008" comment="avahi-tools is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013009" comment="avahi-tools is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090013012" comment="avahi-devel is earlier than 0:0.6.16-1.el5_2.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090013013" comment="avahi-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090014" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0014: kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0014-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0014.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* the sendmsg() function in the Linux kernel did not block during UNIX
socket garbage collection. This could, potentially, lead to a local denial
of service. (CVE-2008-5300, Important)

* when fput() was called to close a socket, the __scm_destroy() function in
the Linux kernel could make indirect recursive calls to itself. This could,
potentially, lead to a local denial of service. (CVE-2008-5029, Important)

* a deficiency was found in the Linux kernel virtual file system (VFS)
implementation. This could allow a local, unprivileged user to make a
series of file creations within deleted directories, possibly causing a
denial of service. (CVE-2008-3275, Moderate)

* a buffer underflow flaw was found in the Linux kernel IB700 SBC watchdog
timer driver. This deficiency could lead to a possible information leak. By
default, the "/dev/watchdog" device is accessible only to the root user.
(CVE-2008-5702, Low)

* the hfs and hfsplus file systems code failed to properly handle corrupted
data structures. This could, potentially, lead to a local denial of
service. (CVE-2008-4933, CVE-2008-5025, Low)

* a flaw was found in the hfsplus file system implementation. This could,
potentially, lead to a local denial of service when write operations were
performed. (CVE-2008-4934, Low)

This update also fixes the following bugs:

* when running Red Hat Enterprise Linux 4.6 and 4.7 on some systems running
Intel® CPUs, the cpuspeed daemon did not run, preventing the CPU speed from
being changed, such as not being reduced to an idle state when not in use.

* mmap() could be used to gain access to beyond the first megabyte of RAM,
due to insufficient checks in the Linux kernel code. Checks have been added
to prevent this.

* attempting to turn keyboard LEDs on and off rapidly on keyboards with
slow keyboard controllers, may have caused key presses to fail.

* after migrating a hypervisor guest, the MAC address table was not
updated, causing packet loss and preventing network connections to the
guest. Now, a gratuitous ARP request is sent after migration. This
refreshes the ARP caches, minimizing network downtime.

* writing crash dumps with diskdump may have caused a kernel panic on
Non-Uniform Memory Access (NUMA) systems with certain memory
configurations.

* on big-endian systems, such as PowerPC, the getsockopt() function
incorrectly returned 0 depending on the parameters passed to it when the
time to live (TTL) value equaled 255, possibly causing memory corruption
and application crashes.

* a problem in the kernel packages provided by the RHSA-2008:0508 advisory
caused the Linux kernel's built-in memory copy procedure to return the
wrong error code after recovering from a page fault on AMD64 and Intel 64
systems. This may have caused other Linux kernel functions to return wrong
error codes.

* a divide-by-zero bug in the Linux kernel process scheduler, which may
have caused kernel panics on certain systems, has been resolved.

* the netconsole kernel module caused the Linux kernel to hang when slave
interfaces of bonded network interfaces were started, resulting in a system
hang or kernel panic when restarting the network.

* the "/proc/xen/" directory existed even if systems were not running Red
Hat Virtualization. This may have caused problems for third-party software
that checks virtualization-ability based on the existence of "/proc/xen/".
Note: this update will remove the "/proc/xen/" directory on systems not
running Red Hat Virtualization.

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-14" />
        <updated date="2009-01-14" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3275">CVE-2008-3275</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4933">CVE-2008-4933</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4934">CVE-2008-4934</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5025">CVE-2008-5025</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029">CVE-2008-5029</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5300">CVE-2008-5300</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5702">CVE-2008-5702</cve>
                <bugzilla href="http://bugzilla.redhat.com/470201" id="470201">CVE-2008-5029 kernel: Unix sockets kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470034" id="470034">HP-Japan: RHEL4.6 diskdump fails when NUMA is on</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470196" id="470196">getsockopt() returning incorrectly in PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471015" id="471015">RHSA-2008:0508 linux-2.6.9-x86_64-copy_user-zero-tail.patch broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471391" id="471391">netconsole hang the system on ifenslave operation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471222" id="471222">erroneous load balancing for isolated CPUs leads to divide-by-zero panic in find_busiest_group()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457858" id="457858">CVE-2008-3275 Linux kernel local filesystem DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/248710" id="248710">Local keyboard DoS through LED switching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476534" id="476534">Xen balloon driver on RHEL4 x86_64 with 2.6.9-78.0.1.ELsmp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469631" id="469631">CVE-2008-4933 kernel: hfsplus: fix Buffer overflow with a corrupted image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469640" id="469640">CVE-2008-4934 kernel: hfsplus: check read_mapping_page() return value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470769" id="470769">CVE-2008-5025 kernel: hfs: fix namelength memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473259" id="473259">CVE-2008-5300 kernel: fix soft lockups/OOM issues with unix socket garbage collector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475733" id="475733">CVE-2008-5702 kernel: watchdog: ib700wdt.c - buffer_underflow bug</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460862" id="460862">kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-4.7.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469891" id="469891">lost packets when live migrating (RHEL4 XEN)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014006" comment="kernel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014004" comment="kernel-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014002" comment="kernel-doc is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel-doc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014018" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-smp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014020" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014010" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014008" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014022" comment="kernel-xenU is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-xenU is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014014" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014016" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090014012" comment="kernel-smp is earlier than 0:2.6.9-78.0.13.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090018" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0018: xterm security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0018-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0018.html" />
    <description>The xterm program is a terminal emulator for the X Window System.

A flaw was found in the xterm handling of Device Control Request Status
String (DECRQSS) escape sequences. An attacker could create a malicious
text file (or log entry, if unfiltered) that could run arbitrary commands
if read by a victim inside an xterm window. (CVE-2008-2383)

All xterm users are advised to upgrade to the updated package, which
contains a backported patch to resolve this issue. All running instances of
xterm must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-07" />
        <updated date="2009-01-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2383">CVE-2008-2383</cve>
                <bugzilla href="http://bugzilla.redhat.com/478888" id="478888">CVE-2008-2383 xterm: arbitrary command injection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018002" comment="xterm is earlier than 0:215-5.el5_2.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018003" comment="xterm is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018005" comment="xterm is earlier than 0:179-11.EL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018006" comment="xterm is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018008" comment="xterm is earlier than 0:192-8.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090018006" comment="xterm is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090020" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0020: bind security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0020-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0020.html" />
    <description>BIND (Berkeley Internet Name Domain) is an implementation of the DNS
(Domain Name System) protocols.

A flaw was discovered in the way BIND checked the return value of the
OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone
could present a malformed DSA certificate and bypass proper certificate
validation, allowing spoofing attacks. (CVE-2009-0025)

For users of Red Hat Enterprise Linux 3 this update also addresses a bug
which can cause BIND to occasionally exit with an assertion failure.

All BIND users are advised to upgrade to the updated package, which
contains a backported patch to resolve this issue. After installing the
update, BIND daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-08" />
        <updated date="2009-01-08" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0025">CVE-2009-0025</cve>
                <bugzilla href="http://bugzilla.redhat.com/478984" id="478984">CVE-2009-0025 bind: DSA_do_verify() returns check issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461047" id="461047">named dies due to assertion failure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020016" comment="bind-utils is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020017" comment="bind-utils is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020012" comment="bind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020013" comment="bind-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020004" comment="bind-chroot is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020005" comment="bind-chroot is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020002" comment="bind-libbind-devel is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020003" comment="bind-libbind-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020008" comment="bind-sdb is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020009" comment="bind-sdb is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020006" comment="bind is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020007" comment="bind is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020010" comment="bind-libs is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020011" comment="bind-libs is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020014" comment="caching-nameserver is earlier than 30:9.3.4-6.0.3.P1.el5_2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020015" comment="caching-nameserver is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020025" comment="bind-devel is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020026" comment="bind-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020023" comment="bind-chroot is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020024" comment="bind-chroot is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020021" comment="bind-utils is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020022" comment="bind-utils is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020019" comment="bind is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020020" comment="bind is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020027" comment="bind-libs is earlier than 20:9.2.4-23.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020028" comment="bind-libs is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020034" comment="bind-devel is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020026" comment="bind-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020033" comment="bind-chroot is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020024" comment="bind-chroot is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020030" comment="bind-utils is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020022" comment="bind-utils is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020032" comment="bind is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020020" comment="bind is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090020031" comment="bind-libs is earlier than 20:9.2.4-30.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090020028" comment="bind-libs is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090046" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0046: ntp security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0046-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0046.html" />
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A flaw was discovered in the way the ntpd daemon checked the return value
of the OpenSSL EVP_VerifyFinal function. On systems using NTPv4
authentication, this could lead to an incorrect verification of
cryptographic signatures, allowing time-spoofing attacks. (CVE-2009-0021)

Note: This issue only affects systems that have enabled NTP authentication.
By default, NTP authentication is not enabled.

All ntp users are advised to upgrade to the updated packages, which contain
a backported patch to resolve this issue. After installing the update, the
ntpd daemon will restart automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-29" />
        <updated date="2009-01-29" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0021">CVE-2009-0021</cve>
                <bugzilla href="http://bugzilla.redhat.com/476807" id="476807">CVE-2009-0021 ntp incorrectly checks for malformed signatures</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046002" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046003" comment="ntp is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046005" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046006" comment="ntp is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090057" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0057: squirrelmail security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0057-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0057.html" />
    <description>SquirrelMail is an easy-to-configure, standards-based, webmail package
written in PHP. It includes built-in PHP support for the IMAP and SMTP
protocols, and pure HTML 4.0 page-rendering (with no JavaScript required)
for maximum browser-compatibility, strong MIME support, address books, and
folder manipulation.

The Red Hat SquirrelMail packages provided by the RHSA-2009:0010 advisory
introduced a session handling flaw. Users who logged back into SquirrelMail
without restarting their web browsers were assigned fixed session
identifiers. A remote attacker could make use of that flaw to hijack user
sessions. (CVE-2009-0030)

SquirrelMail users should upgrade to this updated package, which contains a
patch to correct this issue. As well, all users who used affected versions
of SquirrelMail should review their preferences.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-19" />
        <updated date="2009-01-19" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0030">CVE-2009-0030</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1580">CVE-2009-1580</cve>
                <bugzilla href="http://bugzilla.redhat.com/480224" id="480224">Squirrelmail session management broken by security backport</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480488" id="480488">CVE-2009-0030 squirrelmail: session management flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090057002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_2.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090057005" comment="squirrelmail is earlier than 0:1.4.8-9.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090057008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090205" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:0205: dovecot security and bug fix update (Low)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0205-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0205.html" />
    <description>Dovecot is an IMAP server for Linux and UNIX-like systems, primarily
written with security in mind.

A flaw was found in Dovecot's ACL plug-in. The ACL plug-in treated negative
access rights as positive rights, which could allow an attacker to bypass
intended access restrictions. (CVE-2008-4577)

A password disclosure flaw was found with Dovecot's configuration file. If
a system had the "ssl_key_password" option defined, any local user could
view the SSL key password. (CVE-2008-4870)

Note: This flaw did not allow the attacker to acquire the contents of the
SSL key. The password has no value without the key file which arbitrary
users should not have read access to.

To better protect even this value, however, the dovecot.conf file now
supports the "!include_try" directive. The ssl_key_password option should
be moved from dovecot.conf to a new file owned by, and only readable and
writable by, root (ie 0600). This file should be referenced from
dovecot.conf by setting the "!include_try [/path/to/password/file]" option.

Additionally, this update addresses the following bugs:

* the dovecot init script -- /etc/rc.d/init.d/dovecot -- did not check if
the dovecot binary or configuration files existed. It also used the wrong
pid file for checking the dovecot service's status. This update includes a
new init script that corrects these errors.

* the %files section of the dovecot spec file did not include "%dir
%{ssldir}/private". As a consequence, the /etc/pki/private/ directory was
not owned by dovecot. (Note: files inside /etc/pki/private/ were and are
owned by dovecot.) With this update, the missing line has been added to the
spec file, and the noted directory is now owned by dovecot.

* in some previously released versions of dovecot, the authentication
process accepted (and passed along un-escaped) passwords containing
characters that had special meaning to dovecot's internal protocols. This
updated release prevents such passwords from being passed back, instead
returning the error, "Attempted login with password having illegal chars".

Note: dovecot versions previously shipped with Red Hat Enterprise Linux 5
did not allow this behavior. This update addresses the issue above but said
issue was only present in versions of dovecot not previously included with
Red Hat Enterprise Linux 5.

Users of dovecot are advised to upgrade to this updated package, which
addresses these vulnerabilities and resolves these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Low</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-20" />
        <updated date="2009-01-20" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4577">CVE-2008-4577</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4870">CVE-2008-4870</cve>
                <bugzilla href="http://bugzilla.redhat.com/238016" id="238016">Wrong init script</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439369" id="439369">new dovecot security issues from the dovecot site</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436287" id="436287">dovecot.conf is world readable - possible password exposure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448089" id="448089">dovecot should own /etc/pki/dovecot/private directory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467436" id="467436">CVE-2008-4577 dovecot: incorrect handling of negative rights in the ACL plugin</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469659" id="469659">CVE-2008-4870 dovecot: ssl_key_password disclosure due to an insecure dovecot.conf permissions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090205002" comment="dovecot is earlier than 0:1.0.7-7.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090205003" comment="dovecot is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090225" version="304" class="patch">
      <metadata>
        <title>RHSA-2009:0225: Red Hat Enterprise Linux 5.3 kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0225-03" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0225.html" />
    <description>The Linux kernel (the core of the Linux operating system)

These updated packages contain 730 bug fixes and enhancements for the Linux
kernel. Space precludes a detailed description of each of these changes in
this advisory and users are therefore directed to the release notes for Red
Hat Enterprise Linux 5.3 for information on 97 of the most significant of
these changes. 

Details of three security-related bug fixes are set out below, along with
notes on other broad categories of change not covered in the release notes.
For more detailed information on specific bug fixes or enhancements, please
consult the Bugzilla numbers listed in this advisory.

* when fput() was called to close a socket, the __scm_destroy() function  
in the Linux kernel could make indirect recursive calls to itself. This  
could, potentially, lead to a denial of service issue. (CVE-2008-5029,  
Important)

* a flaw was found in the Asynchronous Transfer Mode (ATM) subsystem. A
local, unprivileged user could use the flaw to listen on the same socket
more than once, possibly causing a denial of service. (CVE-2008-5079,
Important)

* a race condition was found in the Linux kernel "inotify" watch removal
and umount implementation. This could allow a local, unprivileged user  
to cause a privilege escalation or a denial of service. (CVE-2008-5182,  
Important)

* Bug fixes and enhancements are provided for:

* support for specific NICs, including products from the following
manufacturers:
Broadcom
Chelsio
Cisco
Intel
Marvell
NetXen
Realtek
Sun

* Fiber Channel support, including support for Qlogic qla2xxx,
qla4xxx, and qla84xx HBAs and the FCoE, FCP, and zFCP protocols.

* support for various CPUs, including:
AMD Opteron processors with 45 nm SOI ("Shanghai")
AMD Turion Ultra processors
Cell processors
Intel Core i7 processors

* Xen support, including issues specific to the IA64 platform, systems
using AMD processors, and Dell Optiplex GX280 systems

* ext3, ext4, GFS2, NFS, and SPUFS

* Infiniband (including eHCA, eHEA, and IPoIB) support

* common I/O (CIO), direct I/O (DIO), and queued direct I/O (qdio) support

* the kernel distributed lock manager (DLM)

* hardware issues with: SCSI, IEEE 1394 (FireWire), RAID (including issues
specific to Adaptec controllers), SATA (including NCQ), PCI, audio, serial
connections, tape-drives, and USB

* ACPI, some of a general nature and some related to specific hardware
including: certain Lenovo Thinkpad notebooks, HP DC7700 systems, and
certain machines based on Intel Centrino processor technology.

* CIFS, including Kerberos support and a tech-preview of DFS support

* networking support, including IPv6, PPPoE, and IPSec

* support for Intel chipsets, including:
Intel Cantiga chipsets
Intel Eagle Lake chipsets
Intel i915 chipsets
Intel i965 chipsets
Intel Ibex Peak chipsets
Intel chipsets offering QuickPath Interconnects (QPI)

* device mapping issues, including some in device mapper itself

* various issues specific to IA64 and PPC

* CCISS, including support for Compaq SMART Array controllers P711m and
P712m and other new hardware

* various issues affecting specific HP systems, including:
DL785G5
XW4800
XW8600
XW8600
XW9400

* IOMMU support, including specific
issues with AMD and IBM Calgary hardware

* the audit subsystem

* DASD support

* iSCSI support, including issues specific to Chelsio T3 adapters

* LVM issues

* SCTP management information base (MIB) support

* issues with: autofs, kdump, kobject_add, libata, lpar, ptrace, and utrace

* IBM Power platforms using Enhanced I/O Error Handling (EEH)

* EDAC issues for AMD K8 and Intel i5000

* ALSA, including support for new hardware

* futex support

* hugepage support

* Intelligent Platform Management Interface (IPMI) support

* issues affecting NEC/Stratus servers

* OFED support

* SELinux 

* various Virtio issues

All users are advised to upgrade to these updated packages, which resolve
these issues and add these enhancements.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-01-20" />
        <updated date="2009-01-20" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5029">CVE-2008-5029</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5079">CVE-2008-5079</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5182">CVE-2008-5182</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5300">CVE-2008-5300</cve>
                <bugzilla href="http://bugzilla.redhat.com/459436" id="459436">ext4 assembly bitops failures on s390</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470201" id="470201">CVE-2008-5029 kernel: Unix sockets kernel panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438761" id="438761">LTC:5.4:201049:DM-MP SCSI Hardware Handlers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449668" id="449668">RHEL5.3: update ecryptfs kernelspace to 2.6.26 codebase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471576" id="471576">libata: Avoid overflow in ata_tf_read_block() when tf->hba_lbal > 127</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471903" id="471903">[Broadcom 5.3 bug] bnx2: add PCI-IDs for 5716s</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458620" id="458620">Problem with aic79xx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468915" id="468915">[Stratus/NEC 5.3 bug] System can crash when removing input device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434538" id="434538">sr #1768018 : numlock led does not reflect the status of numlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456638" id="456638">[Kdump] not work on HP-XW8600</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469774" id="469774">RHEL53 Beta1: network installation through cxgb3 interface failed if the adapter firmware doesn't match the cxgb3 device driver requst firmware level in rhel53.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466422" id="466422">RHEL5.3: Modify SATA IDE mode quirk</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472095" id="472095">RHEL5.3 e1000e: enable ECC correction on 82571 silicon</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470267" id="470267">cifs: data corruption due to interleaved partial writes timing out</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472382" id="472382">[QLogic 5.3 bug] qla2xx/qla84xx - Failure to establish link.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471269" id="471269">[QLogic 5.3 bug] qla2xxx - No NPIV for Loop connections.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469710" id="469710">Various firewire bugs fixed upstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/412691" id="412691">kernel-xen panic when X shuts down</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451745" id="451745">a check for a buggy HP SAL caused problems booting as a guest in a virtual machine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468922" id="468922">bnx2x + 57711 MCA on BL870c</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451591" id="451591">Handle invalid ACPI SLIT table</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449787" id="449787">FEAT: RHEL5.3 update acpi-cpufreq driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466307" id="466307">/dev/agpart missing for intel i965 HW/82G965 Graphics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469711" id="469711">firewire module unload hangs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463277" id="463277">RHEL5.3: ext4 warning on x86 build</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465856" id="465856">GFS2: recovery stuck</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463478" id="463478">RHEL5.3: ecryptfs memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462622" id="462622">spufs in RHEL5.3: missing context switch notification log</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466774" id="466774">[RHEL5.3] kernel kernel BUG at kernel/exit.c:1129!</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459460" id="459460">kernel: cpufreq: fix format string bug [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472325" id="472325">CVE-2008-5182 kernel: fix inotify watch removal/umount races</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459722" id="459722">[QLogic 5.3 feat] [3/n] qla2xxx - Upstream updates: 8.02.00-k5 to 8.02.00-k6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459527" id="459527">Performance degradation due to excessive spinlocking in the block layer when using logical volume that spans too many physical volumes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459585" id="459585">dlm_recoverd in D state when using IPv6 to comunicate between nodes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459463" id="459463">kernel: binfmt_misc.c: avoid potential kernel stack overflow [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460063" id="460063">CIFS option forcedirectio fails to allow the appending of text to files.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460857" id="460857">kernel: devmem: add range_is_allowed() check to mmap_mem() [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460593" id="460593">backport upstream kernel support for private futexes to RHEL 5.3 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460845" id="460845">Nested LVM can cause deadlock due to kcopyd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460846" id="460846">Deadlock possibility with nested LVMs with snapshots</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438153" id="438153">Poor LVM mirroring performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439918" id="439918">kernel: dio: zero struct dio with kzalloc instead of manually [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446250" id="446250">IPV6DOD: xfrm reverse icmp feature does not seem to work correctly.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471112" id="471112">gdb on ppc hangs, then panics with a kill -9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473110" id="473110">RHEL 5.3: allow tun/tap support larger MTU sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469754" id="469754">kernel panic seen in ptrace_induce_signal in run of rhts test /tools/gdb/gdb-any/</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472844" id="472844">kernel panic when modprobe -r acpi_cpufreq on centrino platform with kernel newer than 2.6.18-118</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471801" id="471801">statically linked uuid segfaults in uuid_generate() on Xen kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466246" id="466246">Interactive installation fails with ext4dev root partition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473114" id="473114">RHEL 5.3: allow virtio_net support larger MTU sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473120" id="473120">RHEL 5.3: implement virtio_net mergeable receive buffer allocate scheme</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464445" id="464445">xm trigger &lt;domain> init causes kernel panic.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440506" id="440506">panic in aoe:aoecmd_ata_rsp during direct I/O to lvm [snap,mirror,stripe]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441640" id="441640">RHEL 5.1 will incorrectly mark SCSI devices as offline due to improper error handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445211" id="445211">[RFE] DTR/DSR flow control</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442736" id="442736">launching too many guests panics with "No available IRQ to bind to: increase NR_IRQS!"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444776" id="444776">iBFT target info not parsed properly by the iscsi_ibft module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443395" id="443395">cp -p does not copy mtime to CIFS share</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446142" id="446142">CIFS: slab error in kmem_cache_destroy(): cache `cifs_request': Can't free all objects</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472504" id="472504">Need to build xen-platform-pci as a module and not into the kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471933" id="471933">[Brocade/Dell 5.3 bug] hts failing memory test with EDAC i5000 Non-Fatal error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452175" id="452175">kernel BUG at arch/i386/mm/highmem-xen.c:43! with errata/RHBA-2008-0314 installed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470625" id="470625">Netdump not functioning w/ bnx2 >= v1.8h (Broadcom Netxtreme II Network Card)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471871" id="471871">dlm: fix up memory allocation flags</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461184" id="461184">Significant regression in time() performance</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451593" id="451593">Multiple outstanding ptc.g instruction support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451586" id="451586">RHEL5.3: SB600/700 SATA controller PMP support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450566" id="450566">FEAT: RHEL5.3 backport fallocate syscall</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446962" id="446962">Access to firewire devices is still allowed after the device is removed from the bus.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447400" id="447400">CIFS VFS: Send error in FindClose = -9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451945" id="451945">Update 3w-xxxx to version 1.26.03.000-2.6.18RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451946" id="451946">Update 3w-9xxx to version 2.26.08.003-2.6.18RH</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453462" id="453462">update CIFS for RHEL5.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453441" id="453441">[QLogic 5.3 bug] qla2xxx- provide additional statistics to user</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453685" id="453685">[QLogic 5.3 feat] [1/n] qla2xxx- Upstream updates: 8.01.07-k7</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453574" id="453574">virtual ethernet device stops working on reception of duplicate backend state change signals</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452577" id="452577">Actual &amp; placeholder funcs have differing param counts</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454711" id="454711">'xm info' does not show correct info in 'node_to_cpu' field on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455308" id="455308">Altix Partitioned System</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455447" id="455447">FEAT: RHEL 5.3: (1/2) Increase deep idle state residency on idle platforms using Nehalem class processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455449" id="455449">FEAT: RHEL 5.3: (2/2) Increase deep idle state residency on idle platforms using Nehalem class processors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455452" id="455452">RFE: delalloc helpers for ext4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456169" id="456169">Need to add 3 dlm symbols to the kernel whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455900" id="455900">[QLogic 5.3 feat] qla2xxx - mgmt. API, CT pass thru</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456900" id="456900">[QLogic 5.3 feat] [0/n] qla2xxx- Netlink, FCoE management API</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463206" id="463206">Regression: Tape commands are possibly retried if there is a loss of connectivity while it is running</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455813" id="455813">Under heavy memory usage dma_alloc_coherent does not return aligned address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455504" id="455504">Backport of don't use large pages to map the first 2/4MB of memory form 2.6.26 to RHEL5-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457013" id="457013">pppoe: Check packet length on all receive paths [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457300" id="457300">hang in ad_rx_machine due to second attempt to lock spin_lock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458360" id="458360">enable userspace kernel header check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458019" id="458019">kernel: random32: seeding improvement [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457143" id="457143">RHEL5.3: misc ecryptfs fixes from 2.6.27</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457025" id="457025">ide-cd: fix oops when using growisofs [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458368" id="458368">[5.0] kdump hangs up by Sysrq+C trigger</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458441" id="458441">Make oprofile recognize Nehalem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458718" id="458718">FEAT: RHEL 5.3 ext4 tech preview</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458936" id="458936">write barriers not supported, ext3 does not complain</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459092" id="459092">kernel dm mpath: fix several problems in dm-mapth target error paths</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458824" id="458824">Oprofile need to enable/disable all the counters for intel family 6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459095" id="459095">kernel dm crypt: use cond_resched</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459337" id="459337">dm-snap.c: Data read from snapshot may be corrupt if origin is being written to simultaneously</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453990" id="453990">[RHEL5.3] LTP test failure in inotify02 testcase</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453711" id="453711">[5.2][nfs] ls -l shows outdated timestamp</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464868" id="464868">incorrect ATA7 handing in kernel causing ABRT errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471639" id="471639">max_phys_segments violation with dm-linear + md raid1 + cciss</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466240" id="466240">Question for LUKS device passhprase unreadable when using Xen</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468967" id="468967">iwlagn (Montevina &amp; Santa Rosa) fails to get associated with AP by NetworkManager frequently</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470449" id="470449">system-config-soundcard is not working on RHEL5.3 GA-snapshot1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465825" id="465825">panic in kcopyd during snapshot I/O</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470610" id="470610">[Emulex 5.3 bug] Update lpfc to version 8.2.0.33.3p</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474736" id="474736">[QLogic 5.3 bug] qla4xxx - Add checks for &lt;TargetName, ISID, TargetPortGroupTag></bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474465" id="474465">RHEL5.3: Calgary DMA errors on IBM systems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460103" id="460103">kernel: alsa: asoc: fix double free and memory leak in many codec drivers [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463470" id="463470">Regression: multipath was setting the REQ_FAILFAST flags which caused a performance drop</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/236750" id="236750">When bonding is used and IPV6 is enabled the message of 'kernel: bond0: duplicate address detected!' is output</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461671" id="461671">[RHEL5] nmi: crash during kdump kernel boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462109" id="462109">[qlogic 5.3 bug] qla2xxx - Set rport dev loss timeout consistently</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463416" id="463416">RHEL 5.3: fix scsi regression causing udev to hang loading sr_mod</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447586" id="447586">DM failing path due to a communication failure on a single i/o</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475778" id="475778">[RHEL 5.3 Xen]: Guest hang on FV save/restore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474935" id="474935">fcoe: fix terminate_rport_io related problems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429142" id="429142">RHEL5.2: ecryptfs oops after lower persistent file creation failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446599" id="446599">jbd races lead to EIO for O_DIRECT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476184" id="476184">RHEL5.3 pv guests crash randomly on reboot orders.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/475652" id="475652">kdump panic introduced by hpet fix on systems without HPET</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436966" id="436966">e1000_clean_tx_irq: Detected Tx Unit Hang - 82546EB</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460047" id="460047">Kernel obsoletes existing Driver Updates on install</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461537" id="461537">crypto: hmac(md5) self-test panics system</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458684" id="458684">GFS2: glock deadlock in page fault path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455478" id="455478">2.6.26 backport of "check physical address range in ioremap" into RHEL5-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455491" id="455491">backport of fix endless page faults in mount_block_root for Linux 2.6 from 2.6.26 to RHEL5-U3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450138" id="450138">dlm: move plock code from gfs2</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/382491" id="382491">duplicate packet from ipt_CLUSTERIP module</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/376831" id="376831">Read from /proc/ppc64/rtas/error_log does not honor O_NONBLOCK</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/464681" id="464681">[QLogic 5.3 bug] qla2xxx/qla84xxx: Advertise qla84xx firmware rev. fix netlink code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465023" id="465023">[QLogic 5.3 bug] Update qla2xxx version to meet open source standards.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461414" id="461414">[QLogic 5.3 bug] qla2xxx/qla84xx: Fix 128Kb limitation in netlink messages;</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463503" id="463503">EEPROM/NVM of the e1000e becomes corrupted</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453472" id="453472">[aacraid] aac_srb: aac_fib_send failed with status 8195</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453094" id="453094">deadlock when lockd tries to take f_sema that it already has</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445522" id="445522">clean up CIFS build warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458270" id="458270">[TAHI] DAD test failure when ipv6_autoconf=yes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461866" id="461866">net: Enable TSO if supported by at least one device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457892" id="457892">RTL8101E performance problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443645" id="443645">ST Driver causing kernel panic condition</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452761" id="452761">r8169 driver broken in 2.6.18-92+ kernels.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453563" id="453563">RTL8111/8168B network card does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431183" id="431183">utrace: PTRACE_POKEUSR_AREA corrupts ACR0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446076" id="446076">[RHEL5 U2] iwl4965 -> compat module taints kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436004" id="436004">50-75 % drop in nfs-server rewrite performance compared to rhel 4.6+</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435291" id="435291">LTC41974-Pages of a memory mapped NFS file get corrupted.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436068" id="436068">[Areca 5.3 feat] Update arcmsr to version 1.20.00.15.RH1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431365" id="431365">SCSI IO errors do not propagate properly with certain SCSI devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434800" id="434800">xenkbd can crash when probe fails</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/239604" id="239604">[RHEL5] console: kobject_add failed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428275" id="428275">Need EOE (End of Event) audit message sent from kernel.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428277" id="428277">Audit subsystem SIGUSR2 support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425955" id="425955">resize2fs online resize fails with small journal</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440261" id="440261">xen/ia64 asm missing srlz instruction</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439899" id="439899">[RFE] Add uvcvideo module to the kernel.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457798" id="457798">GFS2 : gfs2meta is FUBAR</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437579" id="437579">batch kprobe unregister</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443043" id="443043">fix setuid/setgid clearing by knfsd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455729" id="455729">close system call returns -ERESTARTSYS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448763" id="448763">FEAT: Add rt2x00 drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448764" id="448764">FEAT: Add rtl818x drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455434" id="455434">x86: fix PAE pmd_bad bootup warning</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455230" id="455230">v4l2 ioctl debug messages cannot be turned off</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450921" id="450921">s2io intr_type documentation inaccurate</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451196" id="451196">ip tunnel can't be bound to another device</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456300" id="456300">IPMI: Restrict keyboard io port reservation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445095" id="445095">BusLogic module can't compile in the rhel 5.2 beta kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446188" id="446188">BUG: Don't reserve crashkernel memory > 4 GB on ia64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449948" id="449948">Add gate.lds to Documentation/dontdiff</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452535" id="452535">CONFIG_AUDITSYSCALL requires SELinux</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453038" id="453038">Missing functions in UP kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455424" id="455424">x86: show apicid for cpu in proc</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455425" id="455425">x86: don't call MP_processor_info for disabled cpu</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455427" id="455427">x86: don't call MP_processor_info for disabled cpu (64bit)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441615" id="441615">HP DC7700 ACPI problem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444759" id="444759">high I/O wait using 3w-9xxx</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437544" id="437544">fix bad merge in nfs3_write_done and nfs3_commit_done</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/244135" id="244135">audit tty input</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428696" id="428696">nVidia MCP55 MCP55 Ethernet (rev a3) not functional on kernel 2.6.18-53.1.4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453394" id="453394">[RHEL5.2]: Running strace with a bad syscall doesn't return -ENOSYS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455471" id="455471">[NEC/Stratus 5.3 bug] various crashes in md - rdev removed in the middle of ITERATE_RDEV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467689" id="467689">GFS2: Hang when shrink_slab calls gfs2_delete_inode (the GFP_NOFS bit)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/449945" id="449945">Guest OS install causes host machine to crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441716" id="441716">Fake ARP dropped after migration leading to loss of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/466167" id="466167">RHEL5.3: posix-timers race condition causes timer to seize up</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462441" id="462441">Fix NUL handling in TTY input auditing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448328" id="448328">ssh connection hangs when running command producing large text output after running "service iptables restart"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/454792" id="454792">document divider= option in kernel docs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450136" id="450136">dlm: check for null in device_write [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429054" id="429054">soft lockup while unmounting a read-only filesystem with errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/440413" id="440413">ecryptfs module incorrectly checks error codes in process_request_key_err</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437882" id="437882">utrace: orig_rax 0x00000000ffffffff not recognized as -1</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437803" id="437803">gfs2 crash - BUG: unable to handle kernel NULL pointer dereference at virtual address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/433661" id="433661">kernel panic with voip traffic (h323)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457958" id="457958">Backport NetXen nic driver from upstream kernel to RHEL5.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462354" id="462354">dlm: add old plock interface</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459876" id="459876">network hangs and BUG() message at boot with -105.el5debug kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467845" id="467845">RHEL 5.3: allow tcp socket buffers grow to larger than a page size</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/473696" id="473696">CVE-2008-5079 Linux Kernel 'atm module' Local Denial of Service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455460" id="455460">kernel NULL pointer dereference in kobject_get_path</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444611" id="444611">kernel doesn't honor ADDR_NO_RANDOMIZE for stack</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457137" id="457137">[IA64] Fix SMP-unsafe with XENMEM_add_to_physmap on HVM</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451157" id="451157">[Stratus 5.3][2/2] ttyS1 lost interrupt and it stops transmitting</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450855" id="450855">Unbalance reference count in ndisc_recv_ns</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468148" id="468148">getsockopt() returning incorrectly in PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455060" id="455060">PTRACE_KILL does not kill the child process, rather than the child starts running freely.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444865" id="444865">oops in cifs module while trying to stop a thread (kthread_stop) during filesystem mount</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439917" id="439917">kernel: splice: fix bad unlock_page() in error case [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459812" id="459812">IPsec crash with MAC longer than 16 bytes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/465396" id="465396">[5.3] makedumpfile: Can't get necessary symbols for excluding free pages.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444961" id="444961">softlockup when repeatedly dropping caches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445422" id="445422">Feature: allow panic on softlockup warnings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/463500" id="463500">[RHEL5.3] Kernel-xen Oops EIP is at range_straddles_page_boundary+0x2c/0xd9</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469414" id="469414">[QLogic 5.3 bug] qla3xxx, qla4xxx- Update version numbers and use new format.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467927" id="467927">[RHEL5] patch enabling deep C states makes a RHTS machine hang on boot</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469444" id="469444">[All Partners 5.3 bug] allow both ACPI code paths to use the same blacklist dmi_table correctly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462117" id="462117">[QLogic 5.3 bug] qla2xxx - Additional residual-count corrections during UNDERRUN handling.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467216" id="467216">avc:  denied  { sys_resource } when using ext4dev partitions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468192" id="468192">writing data to file can fail and cause panic sometimes when using xattr on ecryptfs</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468547" id="468547">RHEL5.3: Regression in ext3/jbd</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468187" id="468187">[autofs4] Incorrect "active offset mount" messages in syslog</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468538" id="468538">dlm: add dlm_posix_set_fsid to kABI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468034" id="468034">RHEL 5.3: minor virtio_net_fixes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468083" id="468083">kernel-xen doesn't boot on Dell Optiplex GX280</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468555" id="468555">[QLogic 5.3 bug] qla2xxx - restore disable by default of MSI, MSI-X</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467244" id="467244">On RHEL 5.2 32 bit rmmod bonding results in a kernel panic when configured in balance-tlb mode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468573" id="468573">[QLogic 5.3 bug] qla2xxx - Correct Atmel flash-part handling</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468873" id="468873">[QLogic 5.3 bug] qla2xxx - fails to report Option Rom version information</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457961" id="457961">kprobes remove causing kernel panic on ia64 with 2.6.18-92.1.10.el5 kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442820" id="442820">IPV6DOD: ESP with 3des-cbc for encrypt and authentication set to "null"</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444582" id="444582">IPV6DOD: all MCAST_* socket options fail  with 32-bit app, 64-bit kernel due to padding</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443853" id="443853">RHEL 5.3 NULL pointer dereferenced in powernowk8_init</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458774" id="458774">Kernel BUG at fs/nfs/namespace.c:103 (:nfs:nfs_follow_mountpoint)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/420961" id="420961">Driver sky2 lost support for Marvell 88E8056 network controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/453680" id="453680">Error in the uhci code causes usb not to work with iommu=calgary boot option</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443618" id="443618">[REG][Xen][5.2beta] cannot open a vmcore of xen-kdump with crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442991" id="442991">Include xenpv-driver in bare metal kernel rpm.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441832" id="441832">mptscsi race between hotremove and mptscsih_bus_reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462743" id="462743">libata: rmmod pata_sil680 never returns from ata_port_detach</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432057" id="432057">GFS2: d_doio stuck in readv() waiting for pagelock.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456334" id="456334">GFS2: glock dumping misses out some glocks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443896" id="443896">RFE: [Ext4 enabler] backport vfs helpers to facilitate ext4 backport and testing</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439193" id="439193">Assertion failure in journal_next_log_block</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/439194" id="439194">Assertion failure in journal_start() at fs/jbd/transaction.c:274: 'handle->h_transaction->t_journal == journal'</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435144" id="435144">whitelist: iounmap(ia64) - Failed ABI dependencies for IA64 mpt SCSI drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451007" id="451007">FEAT: RHEL 5.3 HDA ALSA driver update from mainstream</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438423" id="438423">backport patch to RHEL5 have it flip to synchronous writes when there is a write error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445674" id="445674">Direct I/O cache invalidation after sync writes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/444589" id="444589">xentop - incompatibility between HV and userspace toolset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450786" id="450786">[Stratus 5.3 bug] kernel NULL pointer dereference at usbdev_read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/231369" id="231369">GFS2 will panic if you misspell any mount options</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468870" id="468870">initscripts upgrade from 8.45.17 to 8.45.19 breaks arp_ip_target</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459107" id="459107">[RHEL5.3]: Hang when booting an i386 domU on an i386 HV</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/370471" id="370471">[RFE] Add support for Wacom PTZ-431W to kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/390601" id="390601">[RHEL5] EDAC k8 MC0: extended error code: GART error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442661" id="442661">[5.2][kdump][xen] crash failed to read vmcore from Dom0 Kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456453" id="456453">GFS2: d_rwdirectempty fails with short read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459221" id="459221">RHEL5.3: Patch to support new AMD HDMI Audio</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462663" id="462663">Netboot image for ppc too large</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442723" id="442723">Xen Support more than 16 disk devices (kernel)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460195" id="460195">Need SCSI transport and LLD netlink support.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/461532" id="461532">/proc/xen on bare-metal and FV guests causes multiple issues</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469715" id="469715">libata: avoid overflow in ata_tf_to_lba48() when tf->hba_lbal> 127</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435115" id="435115">kernel freezes when running script which features ecryptfs parts of kernel</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429951" id="429951">[firewire] unable to use disk (fw_sbp2: failed to login to ...)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458749" id="458749">autofs problem with symbolic links</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/228836" id="228836">acpi processor  module displays errors if hyperthreading disabled</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442906" id="442906">libata: sata_nv - disable ADMA by default</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/431868" id="431868">mounting CIFS subshare doesn't autoconvert prepath delimiters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460135" id="460135">CIFS: enable DFS support as tech-preview in RHEL5.3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/434998" id="434998">utrace: ERESTARTSYS from calling a function from a debugger</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459062" id="459062">pppoe: Fix skb_unshare_check call position [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/448762" id="448762">FEAT: Update ieee80211 component and associated drivers</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442426" id="442426">do not limit locked memory when RLIMIT_MEMLOCK is RLIM_INFINITY</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/467153" id="467153">[QLogic 5.3 bug] latest qlogic driver takes several minutes to find LUNs on older qla2xx controller</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443627" id="443627">kernel dm snapshot: PPC64: kernel OOPS during activation of snapshot with small chunksize</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/442577" id="442577">Backport fix for possible data corruption in mark_buffer_dirty on SMP</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/435110" id="435110">fix up remaining sctp MIB problems</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/443522" id="443522">ls shows two /proc/[pid]/limits files for every process</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458988" id="458988">Panic while using pci=use_crs for resource allocation</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459786" id="459786">utrace signal handling bug interferes with systemtap uprobes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458289" id="458289">GFS2: rm on multiple nodes causes panic</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/458760" id="458760">kernel: dlm: dlm/user.c input validation fixes [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/406051" id="406051">Marvell NIC using skge driver loses promiscuous mode on rewiring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/436686" id="436686">tg3.c does not build on sparc with > 2.6.18-53.el5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426096" id="426096">Xenoprof check_ctrs/start/stop fixes for intel family 6</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446068" id="446068">[RHEL5] k8_edac: typo in 'EDAC k8 MC0: GART TLB errorr: '</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/250104" id="250104">RHEL5 Kernel patches for blktap statistics</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/249726" id="249726">Misspellings in RPM description, suggested clarifications</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450130" id="450130">dlm: fixes for mixed endian cluster</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450132" id="450132">dlm: fixes for recovery of user lockspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450133" id="450133">dlm: keep cached master rsbs during recovery</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450135" id="450135">dlm: save master info after failed no-queue request</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429941" id="429941">[RHEL5 U2] Audit fails to shutdown properly</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457058" id="457058">ecryptfs page-sized memory allocations can corrupt memory</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456052" id="456052">kernel: fix array out of bounds when mounting with selinux options [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429950" id="429950">[firewire] unable to use disk (giving up on config rom)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/430300" id="430300">[firewire] ohci iso receive support incomplete</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445787" id="445787">debugfs: file/directory creation error</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/425341" id="425341">Please add vscnprintf and down_write_trylock to KABI Whitelist</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437129" id="437129">Rpm install fails due to missing symbols required in myri10ge-kmod x86_64 rpm</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/254195" id="254195">use after free in nlm subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/423521" id="423521">memory leak on size-8192 buckets with NFSV4</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/428720" id="428720">[RHEL5 U2] Connectathon RHEL5 client to RHEL4 server, Connectathon failure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/432867" id="432867">memory corruption due to portmap call succeeding after parent rpc_clnt has been freed</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437479" id="437479">remove extraneous error field from nfs_readdir_descriptor_t</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/437958" id="437958">/proc/&lt;pid>/environ not always accessible when receiving PTRACE_EVENT_EXIT</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457006" id="457006">ipv6: use timer pending to fix bridge reference count problem [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457018" id="457018">pppoe: Unshare skb before anything else [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451008" id="451008">Rpmbuild generates incorrect packages due to typos in the kernel-2.6.spec file.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/438230" id="438230">ia64: suspecious compile warning in brew</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/350281" id="350281">IPSec Packet has no Non-ESP marker</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/426895" id="426895">fix default route doesn't work.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/243526" id="243526">IPv6 default route does not work</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/445649" id="445649">[PATCH][RHEL5.1] Performance Improvement of fdatasync(2) in case of Overwrite</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/446707" id="446707">Add support for filetype option in audit subsystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447742" id="447742">JBD: Fix typo that could result in filesystem corruption.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/447748" id="447748">GFS2: lock_dlm is not always delivering callbacks in the right order</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450137" id="450137">dlm: fix basts for granted CW waiting PR/CW</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450219" id="450219">bonding driver can leave rtnl_lock unbalanced</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450184" id="450184">Ensure that 'noac' and/or 'actimeo=0' turn off attribute caching</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450276" id="450276">GFS2: cannot use fifo nodes (named pipes)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/451317" id="451317">deadlock when rpc_malloc tries to flush NFS pages</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/452004" id="452004">gfs2: BUG: unable to handle kernel paging request at ffff81002690e000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/455238" id="455238">IPsec memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456215" id="456215">RHEL 5.3 HDA ALSA driver update from upstream 2008-07-22 (fixes and support for new hw)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/456218" id="456218">kernel: serial open/close loop disables irq [rhel-5.3]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/457569" id="457569">dlm get_comm() uses NULL pointer</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459738" id="459738">GFS2: Multiple writer performance issue.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459556" id="459556">[TAHI] no echo reply for loopback address</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462416" id="462416">[QLogic 5.3 bug] Update qla2xxx - PCI EE error handling support</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/462500" id="462500">BUG: warning when pata_sil680 loaded</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/429337" id="429337">Make dm interfaces available for external modules.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225016" comment="kernel-headers is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-headers is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225012" comment="kernel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225024" comment="kernel-doc is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225014" comment="kernel-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225002" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225010" comment="kernel-debug is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225022" comment="kernel-xen-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225018" comment="kernel-kdump is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225004" comment="kernel-debug-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225020" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225006" comment="kernel-PAE is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090225008" comment="kernel-xen is earlier than 0:2.6.18-128.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090256" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0256: firefox security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0256-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0256.html" />
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0352, CVE-2009-0353, CVE-2009-0356)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2009-0354,
CVE-2009-0355)

A flaw was found in the way Firefox treated HTTPOnly cookies. An attacker
able to execute arbitrary JavaScript on a target site using HTTPOnly
cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357)

A flaw was found in the way Firefox treated certain HTTP page caching
directives. A local attacker could steal the contents of sensitive pages
which the page author did not intend to be cached. (CVE-2009-0358)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.6. You can find a link to the Mozilla
advisories in the References section.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.6, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-04" />
        <updated date="2009-02-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0352">CVE-2009-0352</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0353">CVE-2009-0353</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0354">CVE-2009-0354</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355">CVE-2009-0355</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0356">CVE-2009-0356</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0357">CVE-2009-0357</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0358">CVE-2009-0358</cve>
                <bugzilla href="http://bugzilla.redhat.com/456849" id="456849">missing dependency on pkgconfig in the -devel subpackage</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483143" id="483143">CVE-2009-0355 Firefox local file stealing with SessionStore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483139" id="483139">CVE-2009-0352 Firefox layout crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483141" id="483141">CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483142" id="483142">CVE-2009-0354 Firefox XSS using a chrome XBL method and window.eval</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483144" id="483144">CVE-2009-0356 Firefox Chrome privilege escalation via local .desktop files</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483145" id="483145">CVE-2009-0357 Firefox XMLHttpRequest allows reading HTTPOnly cookies</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483150" id="483150">CVE-2009-0358 Firefox directives to not cache pages ignored</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256002" comment="xulrunner is earlier than 0:1.9.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256006" comment="xulrunner-devel is earlier than 0:1.9.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256008" comment="firefox is earlier than 0:3.0.6-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256012" comment="nss is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256013" comment="nss is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256010" comment="nss-tools is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256011" comment="nss-tools is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256016" comment="nss-devel is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256017" comment="nss-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256014" comment="nss-pkcs11-devel is earlier than 0:3.12.2.0-4.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256015" comment="nss-pkcs11-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256019" comment="firefox is earlier than 0:3.0.6-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256023" comment="nss is earlier than 0:3.12.2.0-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256024" comment="nss is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256025" comment="nss-tools is earlier than 0:3.12.2.0-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256026" comment="nss-tools is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090256021" comment="nss-devel is earlier than 0:3.12.2.0-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256022" comment="nss-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090257" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0257: seamonkey security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0257-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0257.html" />
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-0352, CVE-2009-0353)

A flaw was found in the way malformed content was processed. A website
containing specially-crafted content could, potentially, trick a SeaMonkey
user into uploading a local file. (CVE-2009-0355)

A flaw was found in the way SeaMonkey treated HTTPOnly cookies. An attacker
able to execute arbitrary JavaScript on a target site using HTTPOnly
cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches that correct these issues. After installing the update,
SeaMonkey must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-04" />
        <updated date="2009-02-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0352">CVE-2009-0352</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0353">CVE-2009-0353</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355">CVE-2009-0355</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0357">CVE-2009-0357</cve>
                <bugzilla href="http://bugzilla.redhat.com/483143" id="483143">CVE-2009-0355 Firefox local file stealing with SessionStore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483139" id="483139">CVE-2009-0352 Firefox layout crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483141" id="483141">CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483145" id="483145">CVE-2009-0357 Firefox XMLHttpRequest allows reading HTTPOnly cookies</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257006" comment="seamonkey-nspr is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257018" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257012" comment="seamonkey-mail is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257004" comment="seamonkey is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257014" comment="seamonkey-devel is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257020" comment="seamonkey-nss is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257016" comment="seamonkey-chat is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257010" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-nss-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257002" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.32.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257023" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257026" comment="seamonkey-mail is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257024" comment="seamonkey is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257027" comment="seamonkey-devel is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257025" comment="seamonkey-chat is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090257028" comment="seamonkey-js-debugger is earlier than 0:1.0.9-35.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090258" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0258: thunderbird security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0258-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0258.html" />
    <description>Mozilla Thunderbird is a standalone mail and newsgroup client.

Several flaws were found in the processing of malformed HTML mail content.
An HTML mail message containing malicious content could cause Thunderbird
to crash or, potentially, execute arbitrary code as the user running
Thunderbird. (CVE-2009-0352, CVE-2009-0353, CVE-2009-0772, CVE-2009-0774,
CVE-2009-0775)

Several flaws were found in the way malformed content was processed. An
HTML mail message containing specially-crafted content could potentially
trick a Thunderbird user into surrendering sensitive information.
(CVE-2009-0355, CVE-2009-0776)

Note: JavaScript support is disabled by default in Thunderbird. None of
the above issues are exploitable unless JavaScript is enabled.

All Thunderbird users should upgrade to this updated package, which
resolves these issues. All running instances of Thunderbird must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-24" />
        <updated date="2009-03-24" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0352">CVE-2009-0352</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0353">CVE-2009-0353</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0355">CVE-2009-0355</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772">CVE-2009-0772</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774">CVE-2009-0774</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775">CVE-2009-0775</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776">CVE-2009-0776</cve>
                <bugzilla href="http://bugzilla.redhat.com/483143" id="483143">CVE-2009-0355 Firefox local file stealing with SessionStore</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483139" id="483139">CVE-2009-0352 Firefox layout crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483141" id="483141">CVE-2009-0353 Firefox javascript crashes with evidence of memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488287" id="488287">CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488290" id="488290">CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488273" id="488273">CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488283" id="488283">CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090258002" comment="thunderbird is earlier than 0:2.0.0.21-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090258003" comment="thunderbird is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090258005" comment="thunderbird is earlier than 0:1.5.0.12-19.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090258006" comment="thunderbird is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090259" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0259: mod_auth_mysql security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0259-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0259.html" />
    <description>The mod_auth_mysql package includes an extension module for the Apache HTTP
Server which can be used to implement web user authentication against a
MySQL database.

A flaw was found in the way mod_auth_mysql escaped certain
multibyte-encoded strings. If mod_auth_mysql was configured to use a
multibyte character set that allowed a backslash '\' as part of the
character encodings, a remote attacker could inject arbitrary SQL commands
into a login request. (CVE-2008-2384)

Note: This flaw only affected non-default installations where 
AuthMySQLCharacterSet is configured to use one of the affected multibyte
character sets. Installations that did not use the AuthMySQLCharacterSet
configuration option were not vulnerable to this flaw.

All mod_auth_mysql users are advised to upgrade to the updated package,
which contains a backported patch to resolve this issue. After installing
the update, the httpd daemon must be restarted for the fix to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-11" />
        <updated date="2009-02-11" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2384">CVE-2008-2384</cve>
                <bugzilla href="http://bugzilla.redhat.com/480238" id="480238">CVE-2008-2384 mod_auth_mysql: character encoding SQL injection flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090259002" comment="mod_auth_mysql is earlier than 1:3.0.0-3.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090259003" comment="mod_auth_mysql is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090261" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0261: vnc security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0261-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0261.html" />
    <description>Virtual Network Computing (VNC) is a remote display system which allows you
to view a computer's "desktop" environment not only on the machine where it
is running, but from anywhere on the Internet and from a wide variety of
machine architectures.

An insufficient input validation flaw was discovered in the VNC client
application, vncviewer. If an attacker could convince a victim to connect
to a malicious VNC server, or when an attacker was able to connect to
vncviewer running in the "listen" mode, the attacker could cause the
victim's vncviewer to crash or, possibly, execute arbitrary code.
(CVE-2008-4770)

Users of vncviewer should upgrade to these updated packages, which contain
a backported patch to resolve this issue. For the update to take effect,
all running instances of vncviewer must be restarted after the update is
installed.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-11" />
        <updated date="2009-02-11" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4770">CVE-2008-4770</cve>
                <bugzilla href="http://bugzilla.redhat.com/480590" id="480590">CVE-2008-4770 vnc: vncviewer insufficient encoding value validation in CMsgReader::readRect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/471777" id="471777">VNC Free Edition 4.1.3 fixes a  possible security vulnerability only present in the listening viewer. VNC Server is not compromised.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261004" comment="vnc is earlier than 0:4.1.2-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261005" comment="vnc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261002" comment="vnc-server is earlier than 0:4.1.2-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261003" comment="vnc-server is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261009" comment="vnc is earlier than 0:4.0-0.beta4.1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261010" comment="vnc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261007" comment="vnc-server is earlier than 0:4.0-0.beta4.1.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261008" comment="vnc-server is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261013" comment="vnc is earlier than 0:4.0-12.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261010" comment="vnc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090261012" comment="vnc-server is earlier than 0:4.0-12.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090261008" comment="vnc-server is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090264" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0264: kernel security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0264-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0264.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* a memory leak in keyctl handling. A local user could use this flaw to
deplete kernel memory, eventually leading to a denial of service. 
(CVE-2009-0031, Important)

* a buffer overflow in the Linux kernel Partial Reliable Stream Control
Transmission Protocol (PR-SCTP) implementation. This could, potentially,
lead to a denial of service if a Forward-TSN chunk is received with a large
stream ID. (CVE-2009-0065, Important)

* a flaw when handling heavy network traffic on an SMP system with many
cores. An attacker who could send a large amount of network traffic could
create a denial of service. (CVE-2008-5713, Important)

* the code for the HFS and HFS Plus (HFS+) file systems failed to properly
handle corrupted data structures. This could, potentially, lead to a local
denial of service. (CVE-2008-4933, CVE-2008-5025, Low)

* a flaw was found in the HFS Plus (HFS+) file system implementation. This
could, potentially, lead to a local denial of service when write operations
are performed. (CVE-2008-4934, Low)

In addition, these updated packages fix the following bugs:

* when using the nfsd daemon in a clustered setup, kernel panics appeared
seemingly at random. These panics were caused by a race condition in
the device-mapper mirror target. 

* the clock_gettime(CLOCK_THREAD_CPUTIME_ID, ) syscall returned a smaller
timespec value than the result of previous clock_gettime() function
execution, which resulted in a negative, and nonsensical, elapsed time value.

* nfs_create_rpc_client was called with a "flavor" parameter which was
usually ignored and ended up unconditionally creating the RPC client with
an AUTH_UNIX flavor. This caused problems on AUTH_GSS mounts when the
credentials needed to be refreshed. The credops did not match the
authorization type, which resulted in the credops dereferencing an
incorrect part of the AUTH_UNIX rpc_auth struct.

* when copy_user_c terminated prematurely due to reading beyond the end of
the user buffer and the kernel jumped to the exception table entry, the rsi
register was not cleared. This resulted in exiting back to user code with
garbage in the rsi register.

* the hexdump data in s390dbf traces was incomplete. The length of the data
traced was incorrect and the SAN payload was read from a different place
then it was written to.

* when using connected mode (CM) in IPoIB on ehca2 hardware, it was not
possible to transmit any data.

* when an application called fork() and pthread_create() many times and, at
some point, a thread forked a child and then attempted to call the
setpgid() function, then this function failed and returned and ESRCH error
value.

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. Note: for this update to take effect, the
system must be rebooted.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-10" />
        <updated date="2009-02-10" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4933">CVE-2008-4933</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4934">CVE-2008-4934</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5025">CVE-2008-5025</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5713">CVE-2008-5713</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0031">CVE-2009-0031</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0065">CVE-2009-0065</cve>
                <bugzilla href="http://bugzilla.redhat.com/481120" id="481120">oops in mirror_map (dm-raid1.c)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481122" id="481122">[5.3] clock_gettime() syscall returns a smaller timespec value than previous.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481119" id="481119">Kernel panic in auth_rpcgss:__gss_find_upcall</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481117" id="481117">RHSA-2008:0508 linux-2.6.9-x86_64-copy_user-zero-tail.patch broken</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480996" id="480996">zfcp: fix hexdump data in s390dbf traces</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477744" id="477744">CVE-2008-5713 kernel: soft lockup occurs when network load is very high</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480592" id="480592">CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469631" id="469631">CVE-2008-4933 kernel: hfsplus: fix Buffer overflow with a corrupted image</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/469640" id="469640">CVE-2008-4934 kernel: hfsplus: check read_mapping_page() return value</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/470769" id="470769">CVE-2008-5025 kernel: hfs: fix namelength memory corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479812" id="479812">IB/ipoib: data transmission fails in connected mode on any HCA</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478800" id="478800">CVE-2009-0065 kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480576" id="480576">RHEL5.2/3 - setpgid() returns ESRCH in some situations</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264012" comment="kernel-headers is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-headers is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264008" comment="kernel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264024" comment="kernel-doc is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264010" comment="kernel-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264002" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264016" comment="kernel-debug is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264022" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264014" comment="kernel-kdump is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264006" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264018" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264004" comment="kernel-PAE is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090264020" comment="kernel-xen is earlier than 0:2.6.18-128.1.1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090267" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0267: sudo security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0267-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0267.html" />
    <description>The sudo (superuser do) utility allows system administrators to give
certain users the ability to run commands as root with logging.

A flaw was discovered in a way sudo handled group specifications in "run
as" lists in the sudoers configuration file. If sudo configuration allowed
a user to run commands as any user of some group and the user was also a
member of that group, sudo incorrectly allowed them to run defined commands
with the privileges of any system user. This gave the user unintended
privileges. (CVE-2009-0034)

Users of sudo should update to this updated package, which contains a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-05" />
        <updated date="2009-02-05" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0034">CVE-2009-0034</cve>
                <bugzilla href="http://bugzilla.redhat.com/481720" id="481720">CVE-2009-0034 sudo: incorrect handling of groups in Runas_User</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090267002" comment="sudo is earlier than 0:1.6.9p17-3.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090267003" comment="sudo is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090269" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0269: gstreamer-plugins security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0269-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0269.html" />
    <description>The gstreamer-plugins package contains plug-ins used by the GStreamer
streaming-media framework to support a wide variety of media types.

An array indexing error was found in the GStreamer's QuickTime media file
format decoding plug-in. An attacker could create a carefully-crafted
QuickTime media .mov file that would cause an application using GStreamer
to crash or, potentially, execute arbitrary code if played by a victim.
(CVE-2009-0398)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, all applications using GStreamer (such as
nautilus-media) must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-06" />
        <updated date="2009-02-06" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0398">CVE-2009-0398</cve>
                <bugzilla href="http://bugzilla.redhat.com/483740" id="483740">CVE-2009-0398 gstreamer-plugins: Array index error while parsing malformed QuickTime media files</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090269004" comment="gstreamer-plugins-devel is earlier than 0:0.6.0-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269005" comment="gstreamer-plugins-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090269002" comment="gstreamer-plugins is earlier than 0:0.6.0-19" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269003" comment="gstreamer-plugins is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090270" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0270: gstreamer-plugins security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0270-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0270.html" />
    <description>The gstreamer-plugins package contains plugins used by the GStreamer
streaming-media framework to support a wide variety of media types.

A heap buffer overflow was found in the GStreamer's QuickTime media file
format decoding plug-in. An attacker could create a carefully-crafted
QuickTime media .mov file that would cause an application using GStreamer
to crash or, potentially, execute arbitrary code if played by a victim.
(CVE-2009-0397)

All users of gstreamer-plugins are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing the update, all applications using GStreamer (such as rhythmbox)
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-06" />
        <updated date="2009-02-06" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0397">CVE-2009-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/481267" id="481267">CVE-2009-0397 gstreamer-plugins, gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Time-to-sample (stss) atom data</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090270002" comment="gstreamer-plugins-devel is earlier than 0:0.8.5-1.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269005" comment="gstreamer-plugins-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090270004" comment="gstreamer-plugins is earlier than 0:0.8.5-1.EL.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090269003" comment="gstreamer-plugins is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090271" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:0271: gstreamer-plugins-good security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0271-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0271.html" />
    <description>GStreamer is a streaming media framework, based on graphs of filters which
operate on media data. GStreamer Good Plug-ins is a collection of
well-supported, GStreamer plug-ins of good quality released under the LGPL
license.

Multiple heap buffer overflows and an array indexing error were found in
the GStreamer's QuickTime media file format decoding plugin. An attacker
could create a carefully-crafted QuickTime media .mov file that would cause
an application using GStreamer to crash or, potentially, execute arbitrary
code if played by a victim. (CVE-2009-0386, CVE-2009-0387, CVE-2009-0397)

All users of gstreamer-plugins-good are advised to upgrade to these updated
packages, which contain backported patches to correct these issues. After
installing the update, all applications using GStreamer (such as totem or
rhythmbox) must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-06" />
        <updated date="2009-02-06" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0386">CVE-2009-0386</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0387">CVE-2009-0387</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0397">CVE-2009-0397</cve>
                <bugzilla href="http://bugzilla.redhat.com/481267" id="481267">CVE-2009-0397 gstreamer-plugins, gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Time-to-sample (stss) atom data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483736" id="483736">CVE-2009-0386 gstreamer-plugins-good: heap-based buffer overflow while parsing malformed QuickTime media files via crafted Composition Time To Sample (aka ctts) atom data</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483737" id="483737">CVE-2009-0387 gstreamer-plugins-good: Array index error while parsing malformed QuickTime media files via crafted Sync Sample (aka stss) atom data</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090271004" comment="gstreamer-plugins-good-devel is earlier than 0:0.10.9-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090271005" comment="gstreamer-plugins-good-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090271002" comment="gstreamer-plugins-good is earlier than 0:0.10.9-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090271003" comment="gstreamer-plugins-good is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090275" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0275: imap security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0275-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0275.html" />
    <description>The imap package provides server daemons for both the IMAP (Internet
Message Access Protocol) and POP (Post Office Protocol) mail access protocols.

A buffer overflow flaw was discovered in the dmail and tmail mail delivery
utilities shipped with imap. If either of these utilities were used as a
mail delivery agent, a remote attacker could potentially use this flaw to
run arbitrary code as the targeted user by sending a specially-crafted mail
message to the victim. (CVE-2008-5005)

Users of imap should upgrade to these updated packages, which contain a
backported patch to resolve this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-19" />
        <updated date="2009-02-19" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5005">CVE-2008-5005</cve>
                <bugzilla href="http://bugzilla.redhat.com/469667" id="469667">CVE-2008-5005 uw-imap: buffer overflow in dmail and tmail</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090275004" comment="imap-utils is earlier than 1:2002d-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090275005" comment="imap-utils is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090275006" comment="imap-devel is earlier than 1:2002d-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090275007" comment="imap-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090275002" comment="imap is earlier than 1:2002d-15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090275003" comment="imap is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090295" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0295: net-snmp security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0295-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0295.html" />
    <description>The Simple Network Management Protocol (SNMP) is a protocol used for
network management.

It was discovered that the snmpd daemon did not use TCP wrappers correctly,
causing network hosts access restrictions defined in "/etc/hosts.allow" and
"/etc/hosts.deny" to not be honored. A remote attacker could use this flaw
to bypass intended access restrictions. (CVE-2008-6123)

This issue only affected configurations where hosts.allow and hosts.deny
were used to limit access to the SNMP server. To obtain information from
the server, the attacker would have to successfully authenticate, usually
by providing a correct community string.

All net-snmp users should upgrade to these updated packages, which contain
a backported patch to correct this issue. After installing the update, the
snmpd and snmptrapd daemons will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-26" />
        <updated date="2009-03-26" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6123">CVE-2008-6123</cve>
                <bugzilla href="http://bugzilla.redhat.com/485211" id="485211">CVE-2008-6123 net-snmp: incorrect application of hosts access restrictions in hosts.{allow,deny}</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295006" comment="net-snmp-utils is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295007" comment="net-snmp-utils is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295008" comment="net-snmp-libs is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295009" comment="net-snmp-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295010" comment="net-snmp is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295011" comment="net-snmp is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295004" comment="net-snmp-devel is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295005" comment="net-snmp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090295002" comment="net-snmp-perl is earlier than 0:5.0.9-2.30E.27" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090295003" comment="net-snmp-perl is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090296" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0296: icu security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0296-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0296.html" />
    <description>The International Components for Unicode (ICU) library provides robust and
full-featured Unicode services.

A flaw was found in the way ICU processed certain, invalid, encoded data.
If an application used ICU to decode malformed, multibyte, character data,
it may have been possible to bypass certain content protection mechanisms,
or display information in a manner misleading to the user. (CVE-2008-1036)

All users of icu should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-12" />
        <updated date="2009-03-12" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1036">CVE-2008-1036</cve>
                <bugzilla href="http://bugzilla.redhat.com/464168" id="464168">CVE-2008-1036 ICU: Invalid character sequences omission during conversion of some character encodings (XSS attack possible)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296008" comment="libicu is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296009" comment="libicu is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296006" comment="libicu-devel is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296007" comment="libicu-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296004" comment="libicu-doc is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296005" comment="libicu-doc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090296002" comment="icu is earlier than 0:3.6-5.11.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090296003" comment="icu is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090308" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0308: cups security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0308-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0308.html" />
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

The CUPS security advisory, RHSA-2008:0937, stated that it fixed
CVE-2008-3640 for Red Hat Enterprise Linux 3, 4, and 5. It was discovered
this flaw was not properly fixed on Red Hat Enterprise Linux 3, however.
(CVE-2009-0577)

These new packages contain a proper fix for CVE-2008-3640 on Red Hat
Enterprise Linux 3. Red Hat Enterprise Linux 4 and 5 already contain the
appropriate fix for this flaw and do not need to be updated.

Users of cups should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-02-19" />
        <updated date="2009-02-19" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0577">CVE-2009-0577</cve>
                <bugzilla href="http://bugzilla.redhat.com/486052" id="486052">CVE-2009-0577 cups-CVE-2008-3640.patch has been corrupted.</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090308006" comment="cups-devel is earlier than 1:1.1.17-13.3.56" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090308004" comment="cups-libs is earlier than 1:1.1.17-13.3.56" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090308002" comment="cups is earlier than 1:1.1.17-13.3.56" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090313" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0313: wireshark security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0313-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0313.html" />
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

Multiple buffer overflow flaws were found in Wireshark. If Wireshark read
a malformed packet off a network or opened a malformed dump file, it could
crash or, possibly, execute arbitrary code as the user running Wireshark.
(CVE-2008-4683, CVE-2009-0599)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malformed dump file. (CVE-2008-4680, CVE-2008-4681, CVE-2008-4682,
CVE-2008-4684, CVE-2008-4685, CVE-2008-5285, CVE-2009-0600)

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.6, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4680">CVE-2008-4680</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4681">CVE-2008-4681</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4682">CVE-2008-4682</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4683">CVE-2008-4683</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4684">CVE-2008-4684</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4685">CVE-2008-4685</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5285">CVE-2008-5285</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6472">CVE-2008-6472</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0599">CVE-2009-0599</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0600">CVE-2009-0600</cve>
                <bugzilla href="http://bugzilla.redhat.com/485888" id="485888">CVE-2009-0599 wireshark: buffer overflows in NetScreen snoop file reader</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485889" id="485889">CVE-2009-0600 wireshark: denial of service (application crash) via a crafted Tektronix K12 text capture file</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468171" id="468171">CVE-2008-4683 wireshark: DoS (app crash or abort) in Bluetooth ACL dissector  via a packet with an invalid length</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468166" id="468166">CVE-2008-4680 wireshark: DoS (app crash or abort) via malformed USB Request Block (URB).</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468167" id="468167">CVE-2008-4681 wireshark: DoS (app crash or abort) in Bluetooth RFCOMM dissector via unknown packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468169" id="468169">CVE-2008-4682 wireshark: DoS (app abort) via a malformed  .ncf file with an unknown/unexpected packet type</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468174" id="468174">CVE-2008-4684 wireshark: DoS (app crash) via certain series of packets by enabling the (1) PRP or (2) MATE post dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/468175" id="468175">CVE-2008-4685 wireshark: DoS (app crash or abort) in Q.931 dissector via certain packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/472737" id="472737">CVE-2008-5285 wireshark: DoS (infinite loop) in SMTP dissector via large SMTP request</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313004" comment="wireshark is earlier than 0:1.0.6-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313005" comment="wireshark is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313002" comment="wireshark-gnome is earlier than 0:1.0.6-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313003" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313007" comment="wireshark is earlier than 0:1.0.6-EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313009" comment="wireshark-gnome is earlier than 0:1.0.6-EL3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313013" comment="wireshark is earlier than 0:1.0.6-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090313012" comment="wireshark-gnome is earlier than 0:1.0.6-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090315" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0315: firefox security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0315-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0315.html" />
    <description>Mozilla Firefox is an open source Web browser.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-0040, CVE-2009-0771, CVE-2009-0772, CVE-2009-0773, CVE-2009-0774,
CVE-2009-0775)

Several flaws were found in the way malformed content was processed. A
website containing specially-crafted content could, potentially, trick a
Firefox user into surrendering sensitive information. (CVE-2009-0776,
CVE-2009-0777)

For technical details regarding these flaws, please see the Mozilla
security advisories for Firefox 3.0.7. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.7, and which correct these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040">CVE-2009-0040</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0771">CVE-2009-0771</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772">CVE-2009-0772</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0773">CVE-2009-0773</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774">CVE-2009-0774</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775">CVE-2009-0775</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776">CVE-2009-0776</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0777">CVE-2009-0777</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488272" id="488272">CVE-2009-0771 Firefox 3 Layout Engine Crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488287" id="488287">CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488290" id="488290">CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488273" id="488273">CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488276" id="488276">CVE-2009-0773 Firefox 3 crashes in the JavaScript engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488283" id="488283">CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488292" id="488292">CVE-2009-0777 Firefox URL spoofing with invisible control characters</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315006" comment="xulrunner is earlier than 0:1.9.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315002" comment="xulrunner-devel is earlier than 0:1.9.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090315008" comment="firefox is earlier than 0:3.0.7-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090315011" comment="firefox is earlier than 0:3.0.7-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090325" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0325: seamonkey security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0325-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0325.html" />
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-0040, CVE-2009-0772, CVE-2009-0774, CVE-2009-0775)

A flaw was found in the way malformed content was processed. A website
containing specially-crafted content could, potentially, trick a SeaMonkey
user into surrendering sensitive information. (CVE-2009-0776)

All SeaMonkey users should upgrade to these updated packages, which contain
backported patches that correct these issues. After installing the update,
SeaMonkey must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040">CVE-2009-0040</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0772">CVE-2009-0772</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0774">CVE-2009-0774</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0775">CVE-2009-0775</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0776">CVE-2009-0776</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488287" id="488287">CVE-2009-0775 Firefox XUL Linked Clones Double Free Vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488290" id="488290">CVE-2009-0776 Firefox XML data theft via RDFXMLDataSource and cross-domain redirect</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488273" id="488273">CVE-2009-0772 Firefox 2 and 3 - Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488283" id="488283">CVE-2009-0774 Firefox 2 and 3 crashes in the JavaScript engine</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325016" comment="seamonkey-nspr is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325012" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325008" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325006" comment="seamonkey-mail is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325002" comment="seamonkey is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325018" comment="seamonkey-devel is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325014" comment="seamonkey-chat is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325010" comment="seamonkey-nss is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325004" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-nss-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325020" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.34.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325025" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325028" comment="seamonkey is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325024" comment="seamonkey-mail is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325027" comment="seamonkey-devel is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325023" comment="seamonkey-chat is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090325026" comment="seamonkey-js-debugger is earlier than 0:1.0.9-38.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090326" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0326: kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0326-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0326.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* memory leaks were found on some error paths in the icmp_send()
function in the Linux kernel. This could, potentially, cause the network
connectivity to cease. (CVE-2009-0778, Important)

* Chris Evans reported a deficiency in the clone() system call when called
with the CLONE_PARENT flag. This flaw permits the caller (the parent
process) to indicate an arbitrary signal it wants to receive when its child
process exits. This could lead to a denial of service of the parent
process. (CVE-2009-0028, Moderate)

* an off-by-one underflow flaw was found in the eCryptfs subsystem. This
could potentially cause a local denial of service when the readlink()
function returned an error. (CVE-2009-0269, Moderate)

* a deficiency was found in the Remote BIOS Update (RBU) driver for Dell
systems. This could allow a local, unprivileged user to cause a denial of
service by reading zero bytes from the image_type or packet_size files in
"/sys/devices/platform/dell_rbu/". (CVE-2009-0322, Moderate)

* an inverted logic flaw was found in the SysKonnect FDDI PCI adapter
driver, allowing driver statistics to be reset only when the CAP_NET_ADMIN
capability was absent (local, unprivileged users could reset driver
statistics). (CVE-2009-0675, Moderate)

* the sock_getsockopt() function in the Linux kernel did not properly
initialize a data structure that can be directly returned to user-space
when the getsockopt() function is called with SO_BSDCOMPAT optname set.
This flaw could possibly lead to memory disclosure.
(CVE-2009-0676, Moderate)

* the ext2 and ext3 file system code failed to properly handle corrupted
data structures, leading to a possible local denial of service when read
or write operations were performed on a specially-crafted file system.
(CVE-2008-3528, Low)

* a deficiency was found in the libATA implementation. This could,
potentially, lead to a local denial of service. Note: by default, the
"/dev/sg*" devices are accessible only to the root user.
(CVE-2008-5700, Low)

Bug fixes:

* a bug in aic94xx may have caused kernel panics during boot on some
systems with certain SATA disks. (BZ#485909)

* a word endianness problem in the qla2xx driver on PowerPC-based machines
may have corrupted flash-based devices. (BZ#485908)

* a memory leak in pipe() may have caused a system deadlock. The workaround
in Section 1.5, Known Issues, of the Red Hat Enterprise Linux 5.3 Release
Notes Updates, which involved manually allocating extra file descriptors to
processes calling do_pipe, is no longer necessary. (BZ#481576)

* CPU soft-lockups in the network rate estimator. (BZ#481746)

* bugs in the ixgbe driver caused it to function unreliably on some
systems with 16 or more CPU cores. (BZ#483210)

* the iwl4965 driver may have caused a kernel panic. (BZ#483206)

* a bug caused NFS attributes to not update for some long-lived NFS
mounted file systems. (BZ#483201)

* unmounting a GFS2 file system may have caused a panic. (BZ#485910)

* a bug in ptrace() may have caused a panic when single stepping a target.
(BZ#487394)

* on some 64-bit systems, notsc was incorrectly set at boot, causing slow
gettimeofday() calls. (BZ#488239)

* do_machine_check() cleared all Machine Check Exception (MCE) status
registers, preventing the BIOS from using them to determine the cause of
certain panics and errors. (BZ#490433)

* scaling problems caused performance problems for LAPI applications.
(BZ#489457)

* a panic may have occurred on systems using certain Intel WiFi Link 5000
products when booting with the RF Kill switch on. (BZ#489846)

* the TSC is invariant with C/P/T states, and always runs at constant
frequency from now on. (BZ#489310)

All users should upgrade to these updated packages, which contain
backported patches to correct these issues. The system must be rebooted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-01" />
        <updated date="2009-04-01" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3528">CVE-2008-3528</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5700">CVE-2008-5700</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0028">CVE-2009-0028</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0269">CVE-2009-0269</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0322">CVE-2009-0322</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0675">CVE-2009-0675</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676">CVE-2009-0676</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0778">CVE-2009-0778</cve>
                <bugzilla href="http://bugzilla.redhat.com/485910" id="485910">reproducible panic in debugfs_remove when unmounting gfs2 filesystem</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485909" id="485909">Panic at boot if SATA disk is present</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485908" id="485908">[QLogic 5.4 bug] qla2xx - Word-endian problem programming flash on PPC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490433" id="490433">RHEL5.3 (x86_64): MCE handler must not clear status registers on fatal conditions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481576" id="481576">multipath test causes memory leak and eventual system deadlock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481746" id="481746">[RHEL 5] gen_estimator deadlock fix</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/481604" id="481604">CVE-2009-0269 kernel: ecryptfs readlink flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479932" id="479932">CVE-2009-0028 Linux kernel minor signal handling vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482866" id="482866">CVE-2009-0322 kernel: dell_rbu local oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483201" id="483201">NFS problem#3 of IT 106473 - 32-bit jiffy wrap around - NFS inode</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483206" id="483206">Kernel panic in iwl4965 driver</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487394" id="487394">kernel BUG at kernel/ptrace.c:1068</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488239" id="488239">RHEL5 kernel forces notsc on certain systems [C-state support dependant]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486305" id="486305">CVE-2009-0676 kernel: memory disclosure in SO_BSDCOMPAT gsopt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486534" id="486534">CVE-2009-0675 kernel: skfp_ioctl inverted logic flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/485163" id="485163">CVE-2009-0778 kernel: rt_cache leak leads to lack of network connectivity</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489457" id="489457">Lapi takes too long to run</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474495" id="474495">CVE-2008-5700 kernel: enforce a minimum SG_IO timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459577" id="459577">CVE-2008-3528 Linux kernel ext[234] directory corruption denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489846" id="489846">RHEL 5.3 GA kernel panics when RF Kill is on in 5100/5300 AGN</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489310" id="489310">[Intel 5.4 FEAT] TSC keeps running in C3+</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326010" comment="kernel-headers is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-headers is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326004" comment="kernel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326022" comment="kernel-doc is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326014" comment="kernel-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326006" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326020" comment="kernel-debug is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326018" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326002" comment="kernel-kdump is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326008" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326024" comment="kernel-PAE is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326012" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090326016" comment="kernel-xen is earlier than 0:2.6.18-128.1.6.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090329" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:0329: freetype security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0329-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0329.html" />
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide both the FreeType 1 and FreeType 2
font engines.

Tavis Ormandy of the Google Security Team discovered several integer
overflow flaws in the FreeType 2 font engine. If a user loaded a
carefully-crafted font file with an application linked against FreeType 2,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2009-0946)

Chris Evans discovered multiple integer overflow flaws in the FreeType font
engine. If a user loaded a carefully-crafted font file with an application
linked against FreeType, it could cause the application to crash or,
possibly, execute arbitrary code with the privileges of the user running
the application. (CVE-2006-1861)

An integer overflow flaw was found in the way the FreeType font engine
processed TrueType® Font (TTF) files. If a user loaded a carefully-crafted
font file with an application linked against FreeType, it could cause the
application to crash or, possibly, execute arbitrary code with the
privileges of the user running the application. (CVE-2007-2754)

A flaw was discovered in the FreeType TTF font-file format parser when the
TrueType virtual machine Byte Code Interpreter (BCI) is enabled. If a user
loaded a carefully-crafted font file with an application linked against
FreeType, it could cause the application to crash or, possibly, execute
arbitrary code with the privileges of the user running the application.
(CVE-2008-1808)

The CVE-2008-1808 flaw did not affect the freetype packages as distributed
in Red Hat Enterprise Linux 3 and 4, as they are not compiled with TrueType
BCI support. A fix for this flaw has been included in this update as users
may choose to recompile the freetype packages in order to enable TrueType
BCI support. Red Hat does not, however, provide support for modified and
recompiled packages.

Note: For the FreeType 2 font engine, the CVE-2006-1861, CVE-2007-2754,
and CVE-2008-1808 flaws were addressed via RHSA-2006:0500, RHSA-2007:0403,
and RHSA-2008:0556 respectively. This update provides corresponding
updates for the FreeType 1 font engine, included in the freetype packages
distributed in Red Hat Enterprise Linux 3 and 4.

Users are advised to upgrade to these updated packages, which contain
backported patches to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1861">CVE-2006-1861</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2754">CVE-2007-2754</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1808">CVE-2008-1808</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0946">CVE-2009-0946</cve>
                <bugzilla href="http://bugzilla.redhat.com/240200" id="240200">CVE-2007-2754 freetype integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/450774" id="450774">CVE-2008-1808 FreeType off-by-one flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484437" id="484437">CVE-2006-1861 freetype: multiple integer overflow vulnerabilities</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491384" id="491384">CVE-2009-0946 freetype: multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329008" comment="freetype-utils is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329009" comment="freetype-utils is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329002" comment="freetype is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329003" comment="freetype is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329004" comment="freetype-demos is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329005" comment="freetype-demos is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329006" comment="freetype-devel is earlier than 0:2.1.4-12.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329007" comment="freetype-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329013" comment="freetype-utils is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329009" comment="freetype-utils is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329011" comment="freetype is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329003" comment="freetype is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329012" comment="freetype-demos is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329005" comment="freetype-demos is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090329014" comment="freetype-devel is earlier than 0:2.1.9-10.el4.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090329007" comment="freetype-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090331" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0331: kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0331-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0331.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update addresses the following security issues:

* a buffer overflow was found in the Linux kernel Partial Reliable Stream
Control Transmission Protocol (PR-SCTP) implementation. This could,
potentially, lead to a denial of service if a Forward-TSN chunk is received
with a large stream ID. (CVE-2009-0065, Important)

* a memory leak was found in keyctl handling. A local, unprivileged user
could use this flaw to deplete kernel memory, eventually leading to a
denial of service. (CVE-2009-0031, Important)

* a deficiency was found in the Remote BIOS Update (RBU) driver for Dell
systems. This could allow a local, unprivileged user to cause a denial of
service by reading zero bytes from the image_type or packet_size file in
"/sys/devices/platform/dell_rbu/". (CVE-2009-0322, Important)

* a deficiency was found in the libATA implementation. This could,
potentially, lead to a denial of service. Note: by default, "/dev/sg*"
devices are accessible only to the root user. (CVE-2008-5700, Low)

This update also fixes the following bugs:

* when the hypervisor changed a page table entry (pte) mapping from
read-only to writable via a make_writable hypercall, accessing the changed
page immediately following the change caused a spurious page fault. When
trying to install a para-virtualized Red Hat Enterprise Linux 4 guest on a
Red Hat Enterprise Linux 5.3 dom0 host, this fault crashed the installer
with a kernel backtrace. With this update, the "spurious" page fault is
handled properly. (BZ#483748)

* net_rx_action could detect its cpu poll_list as non-empty, but have that
same list reduced to empty by the poll_napi path. This resulted in garbage
data being returned when net_rx_action calls list_entry, which subsequently
resulted in several possible crash conditions. The race condition in the
network code which caused this has been fixed. (BZ#475970, BZ#479681,
BZ#480741)

* a misplaced memory barrier at unlock_buffer() could lead to a concurrent
h_refcounter update which produced a reference counter leak and, later, a
double free in ext3_xattr_release_block(). Consequent to the double free,
ext3 reported an error

    ext3_free_blocks_sb: bit already cleared for block [block number]

and mounted itself as read-only. With this update, the memory barrier is
now placed before the buffer head lock bit, forcing the write order and
preventing the double free. (BZ#476533)

* when the iptables module was unloaded, it was assumed the correct entry
for removal had been found if "wrapper->ops->pf" matched the value passed
in by "reg->pf". If several ops ranges were registered against the same
protocol family, however, (which was likely if you had both ip_conntrack
and ip_contrack_* loaded) this assumption could lead to NULL list pointers
and cause a kernel panic. With this update, "wrapper->ops" is matched to
pointer values "reg", which ensures the correct entry is removed and
results in no NULL list pointers. (BZ#477147)

* when the pidmap page (used for tracking process ids, pids) incremented to
an even page (ie the second, fourth, sixth, etc. pidmap page), the
alloc_pidmap() routine skipped the page. This resulted in "holes" in the
allocated pids. For example, after pid 32767, you would expect 32768 to be
allocated. If the page skipping behavior presented, however, the pid
allocated after 32767 was 65536. With this update, alloc_pidmap() no longer
skips alternate pidmap pages and allocated pid holes no longer occur. This
fix also corrects an error which allowed pid_max to be set higher than the
pid_max limit has been corrected. (BZ#479182)

All Red Hat Enterprise Linux 4 users should upgrade to these updated
packages, which contain backported patches to resolve these issues. The
system must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-12" />
        <updated date="2009-03-12" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5700">CVE-2008-5700</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0031">CVE-2009-0031</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0065">CVE-2009-0065</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0322">CVE-2009-0322</cve>
                <bugzilla href="http://bugzilla.redhat.com/475970" id="475970">oops in e1000_clean (list corruption due to race with e1000_down)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480592" id="480592">CVE-2009-0031 kernel: local denial of service in keyctl_join_session_keyring</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/482866" id="482866">CVE-2009-0322 kernel: dell_rbu local oops</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/483748" id="483748">rhel4 PV guest installations busted on rhel 5.3 i386 intel dom0</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476533" id="476533">Read-only filesystem after 'ext3_free_blocks_sb: bit already cleared for block' errors</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477147" id="477147">Kernel panic when unloading ip conntrack modules</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479182" id="479182">RHEL4 64 bit skips all pids with bit 15 set (32768-65535, 98304-131071 etc)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479681" id="479681">oops in net_rx_action on double free of dev->poll_list</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478800" id="478800">CVE-2009-0065 kernel: sctp: memory overflow when FWD-TSN chunk is received with bad stream ID</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/474495" id="474495">CVE-2008-5700 kernel: enforce a minimum SG_IO timeout</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480741" id="480741">RHEL4.8 kernel crashed in net_rx_action() on IA64 machine in RHTS connectathon test</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331006" comment="kernel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331004" comment="kernel-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331002" comment="kernel-doc is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel-doc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331020" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-smp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331012" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331010" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331008" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331022" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331014" comment="kernel-xenU is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-xenU is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331016" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090331018" comment="kernel-smp is earlier than 0:2.6.9-78.0.17.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090333" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0333: libpng security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0333-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0333.html" />
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was discovered in libpng that could result in libpng trying to
free() random memory if certain, unlikely error conditions occurred. If a
carefully-crafted PNG file was loaded by an application linked against
libpng, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-0040)

A flaw was discovered in the way libpng handled PNG images containing
"unknown" chunks. If an application linked against libpng attempted to
process a malformed, unknown chunk in a malicious PNG image, it could cause
the application to crash. (CVE-2008-1382)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1382">CVE-2008-1382</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040">CVE-2009-0040</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/441839" id="441839">CVE-2008-1382 libpng unknown chunk handling flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333004" comment="libpng is earlier than 2:1.2.10-7.1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333005" comment="libpng is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333002" comment="libpng-devel is earlier than 2:1.2.10-7.1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333003" comment="libpng-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333007" comment="libpng is earlier than 2:1.2.7-3.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333008" comment="libpng is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333009" comment="libpng-devel is earlier than 2:1.2.7-3.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333010" comment="libpng-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333011" comment="libpng10-devel is earlier than 0:1.0.16-3.el4_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333012" comment="libpng10-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090333013" comment="libpng10 is earlier than 0:1.0.16-3.el4_7.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333014" comment="libpng10 is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090336" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0336: glib2 security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0336-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0336.html" />
    <description>GLib is the low-level core library that forms the basis for projects such
as GTK+ and GNOME. It provides data structure handling for C, portability
wrappers, and interfaces for such runtime functionality as an event loop,
threads, dynamic loading, and an object system.

Diego Pettenò discovered multiple integer overflows causing heap-based
buffer overflows in GLib's Base64 encoding and decoding functions. An
attacker could use these flaws to crash an application using GLib's Base64
functions to encode or decode large, untrusted inputs, or, possibly,
execute arbitrary code as the user running the application. (CVE-2008-4316)

Note: No application shipped with Red Hat Enterprise Linux 5 uses the
affected functions. Third-party applications may, however, be affected.

All users of glib2 should upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-24" />
        <updated date="2009-03-24" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4316">CVE-2008-4316</cve>
                <bugzilla href="http://bugzilla.redhat.com/474770" id="474770">CVE-2008-4316 glib2: integer overflows in the base64 handling functions (oCERT-2008-015)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090336004" comment="glib2-devel is earlier than 0:2.12.3-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090336005" comment="glib2-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090336002" comment="glib2 is earlier than 0:2.12.3-4.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090336003" comment="glib2 is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090337" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0337: php security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0337-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0337.html" />
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A heap-based buffer overflow flaw was found in PHP's mbstring extension. A
remote attacker able to pass arbitrary input to a PHP script using mbstring
conversion functions could cause the PHP interpreter to crash or,
possibly, execute arbitrary code. (CVE-2008-5557)

A flaw was found in the handling of the "mbstring.func_overload"
configuration setting. A value set for one virtual host, or in a user's
.htaccess file, was incorrectly applied to other virtual hosts on the same
server, causing the handling of multibyte character strings to not work
correctly. (CVE-2009-0754)

A buffer overflow flaw was found in PHP's imageloadfont function.  If a PHP
script allowed a remote attacker to load a carefully crafted font file, it
could cause the PHP interpreter to crash or, possibly, execute arbitrary
code. (CVE-2008-3658)

A flaw was found in the way PHP handled certain file extensions when
running in FastCGI mode. If the PHP interpreter was being executed via
FastCGI, a remote attacker could create a request which would cause the PHP
interpreter to crash. (CVE-2008-3660)

A memory disclosure flaw was found in the PHP gd extension's imagerotate
function. A remote attacker able to pass arbitrary values as the
"background color" argument of the function could, possibly, view portions
of the PHP interpreter's memory. (CVE-2008-5498)

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The httpd web server
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-06" />
        <updated date="2009-04-06" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658">CVE-2008-3658</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660">CVE-2008-3660</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498">CVE-2008-5498</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5557">CVE-2008-5557</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0754">CVE-2009-0754</cve>
                <bugzilla href="http://bugzilla.redhat.com/459529" id="459529">CVE-2008-3658 php: buffer overflow in the imageloadfont function in gd extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459572" id="459572">CVE-2008-3660 php: FastCGI module DoS via multiple dots preceding the extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478425" id="478425">CVE-2008-5498 php: libgd imagerotate() array index error memory disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479272" id="479272">CVE-2009-0754 PHP mbstring.func_overload web server denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478848" id="478848">CVE-2008-5557 php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337004" comment="php-odbc is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337005" comment="php-odbc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337006" comment="php-mysql is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337007" comment="php-mysql is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337002" comment="php is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337003" comment="php is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337008" comment="php-pgsql is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337009" comment="php-pgsql is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337010" comment="php-devel is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337011" comment="php-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337012" comment="php-imap is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337013" comment="php-imap is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337014" comment="php-ldap is earlier than 0:4.3.2-51.ent" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337015" comment="php-ldap is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337036" comment="php-gd is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337037" comment="php-gd is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337032" comment="php-odbc is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337005" comment="php-odbc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337027" comment="php-mysql is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337007" comment="php-mysql is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337024" comment="php is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337003" comment="php is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337017" comment="php-xmlrpc is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337018" comment="php-xmlrpc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337022" comment="php-mbstring is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337023" comment="php-mbstring is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337033" comment="php-pgsql is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337009" comment="php-pgsql is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337021" comment="php-devel is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337011" comment="php-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337034" comment="php-imap is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337013" comment="php-imap is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337030" comment="php-snmp is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337031" comment="php-snmp is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337019" comment="php-ncurses is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337020" comment="php-ncurses is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337025" comment="php-pear is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337026" comment="php-pear is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337035" comment="php-ldap is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337015" comment="php-ldap is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090337028" comment="php-domxml is earlier than 0:4.3.9-3.22.15" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090337029" comment="php-domxml is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090338" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0338: php security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0338-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0338.html" />
    <description>PHP is an HTML-embedded scripting language commonly used with the Apache
HTTP Web server.

A heap-based buffer overflow flaw was found in PHP's mbstring extension. A
remote attacker able to pass arbitrary input to a PHP script using mbstring
conversion functions could cause the PHP interpreter to crash or,
possibly, execute arbitrary code. (CVE-2008-5557)

A flaw was found in the handling of the "mbstring.func_overload"
configuration setting. A value set for one virtual host, or in a user's
.htaccess file, was incorrectly applied to other virtual hosts on the same
server, causing the handling of multibyte character strings to not work
correctly. (CVE-2009-0754)

A buffer overflow flaw was found in PHP's imageloadfont function.  If a PHP
script allowed a remote attacker to load a carefully crafted font file, it
could cause the PHP interpreter to crash or, possibly, execute arbitrary
code. (CVE-2008-3658)

A flaw was found in the way PHP handled certain file extensions when
running in FastCGI mode. If the PHP interpreter was being executed via
FastCGI, a remote attacker could create a request which would cause the PHP
interpreter to crash. (CVE-2008-3660)

A memory disclosure flaw was found in the PHP gd extension's imagerotate
function. A remote attacker able to pass arbitrary values as the
"background color" argument of the function could, possibly, view portions
of the PHP interpreter's memory. (CVE-2008-5498)

A cross-site scripting flaw was found in a way PHP reported errors for
invalid cookies. If the PHP interpreter had "display_errors" enabled, a
remote attacker able to set a specially-crafted cookie on a victim's system
could possibly inject arbitrary HTML into an error message generated by
PHP. (CVE-2008-5814)

All php users are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. The httpd web server
must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-06" />
        <updated date="2009-04-06" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3658">CVE-2008-3658</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3660">CVE-2008-3660</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5498">CVE-2008-5498</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5557">CVE-2008-5557</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5814">CVE-2008-5814</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0754">CVE-2009-0754</cve>
                <bugzilla href="http://bugzilla.redhat.com/459529" id="459529">CVE-2008-3658 php: buffer overflow in the imageloadfont function in gd extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/459572" id="459572">CVE-2008-3660 php: FastCGI module DoS via multiple dots preceding the extension</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478425" id="478425">CVE-2008-5498 php: libgd imagerotate() array index error memory disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479272" id="479272">CVE-2009-0754 PHP mbstring.func_overload web server denial of service</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/478848" id="478848">CVE-2008-5557 php: Heap-based buffer overflow in the mbstring extension via crafted string containing a HTML entity (arb code execution)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480167" id="480167">CVE-2008-5814 php: XSS via PHP error messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338036" comment="php-odbc is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338037" comment="php-odbc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338024" comment="php-common is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338025" comment="php-common is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338022" comment="php-gd is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338023" comment="php-gd is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338016" comment="php-soap is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338017" comment="php-soap is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338026" comment="php-mysql is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338027" comment="php-mysql is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338014" comment="php is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338015" comment="php is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338002" comment="php-xmlrpc is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338003" comment="php-xmlrpc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338008" comment="php-cli is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338009" comment="php-cli is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338018" comment="php-mbstring is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338019" comment="php-mbstring is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338032" comment="php-xml is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338033" comment="php-xml is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338030" comment="php-pgsql is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338031" comment="php-pgsql is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338028" comment="php-devel is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338029" comment="php-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338020" comment="php-dba is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338021" comment="php-dba is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338034" comment="php-imap is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338035" comment="php-imap is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338012" comment="php-snmp is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338013" comment="php-snmp is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338006" comment="php-bcmath is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338007" comment="php-bcmath is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338004" comment="php-ncurses is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338005" comment="php-ncurses is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338038" comment="php-pdo is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338039" comment="php-pdo is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090338010" comment="php-ldap is earlier than 0:5.1.6-23.2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090338011" comment="php-ldap is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090339" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0339: lcms security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0339-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0339.html" />
    <description>Little Color Management System (LittleCMS, or simply "lcms") is a
small-footprint, speed-optimized open source color management engine.

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in LittleCMS. An attacker could use these flaws to create a
specially-crafted image file which could cause an application using
LittleCMS to crash, or, possibly, execute arbitrary code when opened by a
victim. (CVE-2009-0723, CVE-2009-0733)

A memory leak flaw was found in LittleCMS. An application using LittleCMS
could use excessive amount of memory, and possibly crash after using all
available memory, if used to open specially-crafted images. (CVE-2009-0581)

Red Hat would like to thank Chris Evans from the Google Security Team for
reporting these issues.

All users of LittleCMS should install these updated packages, which upgrade
LittleCMS to version 1.18. All running applications using the lcms library
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581">CVE-2009-0581</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723">CVE-2009-0723</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733">CVE-2009-0733</cve>
                <bugzilla href="http://bugzilla.redhat.com/487512" id="487512">CVE-2009-0733 LittleCms lack of upper-bounds check on sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487509" id="487509">CVE-2009-0581 LittleCms memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487508" id="487508">CVE-2009-0723 LittleCms integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090339004" comment="lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011007" comment="lcms is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090339006" comment="lcms-devel is earlier than 0:1.18-0.1.beta1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011003" comment="lcms-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090339002" comment="python-lcms is earlier than 0:1.18-0.1.beta1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090011005" comment="python-lcms is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090340" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0340: libpng security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0340-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0340.html" />
    <description>The libpng packages contain a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files.

A flaw was discovered in libpng that could result in libpng trying to
free() random memory if certain, unlikely error conditions occurred. If a
carefully-crafted PNG file was loaded by an application linked against
libpng, it could cause the application to crash or, potentially, execute
arbitrary code with the privileges of the user running the application.
(CVE-2009-0040)

Users of libpng and libpng10 should upgrade to these updated packages,
which contain backported patches to correct these issues. All running
applications using libpng or libpng10 must be restarted for the update to
take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-04" />
        <updated date="2009-03-04" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0040">CVE-2009-0040</cve>
                <bugzilla href="http://bugzilla.redhat.com/486355" id="486355">CVE-2009-0040 libpng arbitrary free() flaw</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340002" comment="libpng is earlier than 2:1.2.2-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333008" comment="libpng is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340004" comment="libpng-devel is earlier than 2:1.2.2-29" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333010" comment="libpng-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340008" comment="libpng10-devel is earlier than 0:1.0.13-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333012" comment="libpng10-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090340006" comment="libpng10 is earlier than 0:1.0.13-20" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090333014" comment="libpng10 is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090341" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0341: curl security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0341-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0341.html" />
    <description>cURL is a tool for getting files from FTP, HTTP, Gopher, Telnet, and Dict
servers, using any of the supported protocols. cURL is designed to work
without user interaction or any kind of interactivity.

David Kierznowski discovered a flaw in libcurl where it would not
differentiate between different target URLs when handling automatic
redirects. This caused libcurl to follow any new URL that it understood,
including the "file://" URL type. This could allow a remote server to force
a local libcurl-using application to read a local file instead of the
remote one, possibly exposing local files that were not meant to be
exposed. (CVE-2009-0037)

Note: Applications using libcurl that are expected to follow redirects to
"file://" protocol must now explicitly call curl_easy_setopt(3) and set the
newly introduced CURLOPT_REDIR_PROTOCOLS option as required.

cURL users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running applications using
libcurl must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0037">CVE-2009-0037</cve>
                <bugzilla href="http://bugzilla.redhat.com/485271" id="485271">CVE-2009-0037 curl: local file access via unsafe redirects</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341004" comment="curl is earlier than 0:7.15.5-2.1.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341005" comment="curl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341002" comment="curl-devel is earlier than 0:7.15.5-2.1.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341003" comment="curl-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341009" comment="curl is earlier than 0:7.10.6-9.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341010" comment="curl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341007" comment="curl-devel is earlier than 0:7.10.6-9.rhel3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341008" comment="curl-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341012" comment="curl is earlier than 0:7.12.1-11.1.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341010" comment="curl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090341013" comment="curl-devel is earlier than 0:7.12.1-11.1.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090341008" comment="curl-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090344" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0344: libsoup security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0344-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0344.html" />
    <description>libsoup is an HTTP client/library implementation for GNOME written in C. It
was originally part of a SOAP (Simple Object Access Protocol)
implementation called Soup, but the SOAP and non-SOAP parts have now been
split into separate packages.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in libsoup's Base64 encoding routine. An attacker could use this
flaw to crash, or, possibly, execute arbitrary code. This arbitrary code
would execute with the privileges of the application using libsoup's Base64
routine to encode large, untrusted inputs. (CVE-2009-0585)

All users of libsoup and evolution28-libsoup should upgrade to these
updated packages, which contain a backported patch to resolve this issue.
All running applications using the affected library function (such as
Evolution configured to connect to the GroupWise back-end) must be
restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0585">CVE-2009-0585</cve>
                <bugzilla href="http://bugzilla.redhat.com/488026" id="488026">CVE-2009-0585 libsoup: integer overflow in soup_base64_encode()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344004" comment="libsoup-devel is earlier than 0:2.2.98-2.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344005" comment="libsoup-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344002" comment="libsoup is earlier than 0:2.2.98-2.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344003" comment="libsoup is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344009" comment="libsoup-devel is earlier than 0:2.2.1-4.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344010" comment="libsoup-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344007" comment="libsoup is earlier than 0:2.2.1-4.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344008" comment="libsoup is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344013" comment="evolution28-libsoup-devel is earlier than 0:2.2.98-5.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344014" comment="evolution28-libsoup-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090344011" comment="evolution28-libsoup is earlier than 0:2.2.98-5.el4.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090344012" comment="evolution28-libsoup is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090352" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0352: gstreamer-plugins-base security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0352-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0352.html" />
    <description>GStreamer is a streaming media framework based on graphs of filters which
operate on media data. GStreamer Base Plug-ins is a collection of
well-maintained base plug-ins.

An integer overflow flaw which caused a heap-based buffer overflow was
discovered in the Vorbis comment tags reader. An attacker could create a
carefully-crafted Vorbis file that would cause an application using
GStreamer to crash or, potentially, execute arbitrary code if opened by a
victim. (CVE-2009-0586)

All users of gstreamer-plugins-base are advised to upgrade to these updated
packages, which contain a backported patch to correct this issue. After
installing this update, all applications using GStreamer (such as Totem or
Rhythmbox) must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-06" />
        <updated date="2009-04-06" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0586">CVE-2009-0586</cve>
                <bugzilla href="http://bugzilla.redhat.com/488208" id="488208">CVE-2009-0586 gstreamer-plugins-base: integer overflow in gst_vorbis_tag_add_coverart()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090352002" comment="gstreamer-plugins-base is earlier than 0:0.10.20-3.0.1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090352003" comment="gstreamer-plugins-base is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090352004" comment="gstreamer-plugins-base-devel is earlier than 0:0.10.20-3.0.1.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090352005" comment="gstreamer-plugins-base-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090354" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0354: evolution-data-server security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0354-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0354.html" />
    <description>Evolution Data Server provides a unified back-end for applications which
interact with contacts, task, and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.

Evolution Data Server did not properly check the Secure/Multipurpose
Internet Mail Extensions (S/MIME) signatures used for public key encryption
and signing of e-mail messages. An attacker could use this flaw to spoof a
signature by modifying the text of the e-mail message displayed to the
user. (CVE-2009-0547)

It was discovered that Evolution Data Server did not properly validate NTLM
(NT LAN Manager) authentication challenge packets. A malicious server using
NTLM authentication could cause an application using Evolution Data Server
to disclose portions of its memory or crash during user authentication.
(CVE-2009-0582)

Multiple integer overflow flaws which could cause heap-based buffer
overflows were found in the Base64 encoding routines used by Evolution Data
Server. This could cause an application using Evolution Data Server to
crash, or, possibly, execute an arbitrary code when large untrusted data
blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution-data-server and evolution28-evolution-data-server
are advised to upgrade to these updated packages, which contain backported
patches to correct these issues. All running instances of Evolution Data
Server and applications using it (such as Evolution) must be restarted for
the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547">CVE-2009-0547</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0582">CVE-2009-0582</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587">CVE-2009-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/487685" id="487685">CVE-2009-0582 evolution-data-server: insufficient checking of NTLM authentication challenge packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488226" id="488226">CVE-2009-0587 evolution-data-server: integer overflow in base64 encoding functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484925" id="484925">CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354006" comment="evolution-data-server-doc is earlier than 0:1.12.3-10.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354007" comment="evolution-data-server-doc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354002" comment="evolution-data-server is earlier than 0:1.12.3-10.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354003" comment="evolution-data-server is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354004" comment="evolution-data-server-devel is earlier than 0:1.12.3-10.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354005" comment="evolution-data-server-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354011" comment="evolution28-evolution-data-server is earlier than 0:1.8.0-37.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354012" comment="evolution28-evolution-data-server is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090354009" comment="evolution28-evolution-data-server-devel is earlier than 0:1.8.0-37.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090354010" comment="evolution28-evolution-data-server-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090355" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0355: evolution and evolution-data-server security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0355-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0355.html" />
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

Evolution Data Server provides a unified back-end for applications which
interact with contacts, task and calendar information. Evolution Data
Server was originally developed as a back-end for Evolution, but is now
used by multiple other applications.

Evolution did not properly check the Secure/Multipurpose Internet Mail
Extensions (S/MIME) signatures used for public key encryption and signing
of e-mail messages. An attacker could use this flaw to spoof a signature by
modifying the text of the e-mail message displayed to the user. (CVE-2009-0547)

It was discovered that evolution did not properly validate NTLM (NT LAN
Manager) authentication challenge packets. A malicious server using NTLM
authentication could cause evolution to disclose portions of its memory or
crash during user authentication. (CVE-2009-0582)

Multiple integer overflow flaws which could cause heap-based buffer
overflows were found in the Base64 encoding routines used by evolution and
evolution-data-server. This could cause evolution, or an application using
evolution-data-server, to crash, or, possibly, execute an arbitrary code
when large untrusted data blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution and evolution-data-server are advised to upgrade to
these updated packages, which contain backported patches to correct these
issues. All running instances of evolution and evolution-data-server must
be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0547">CVE-2009-0547</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0582">CVE-2009-0582</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587">CVE-2009-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/487685" id="487685">CVE-2009-0582 evolution-data-server: insufficient checking of NTLM authentication challenge packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488226" id="488226">CVE-2009-0587 evolution-data-server: integer overflow in base64 encoding functions</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484925" id="484925">CVE-2009-0547 evolution-data-server: S/MIME signatures are considered to be valid even for modified messages (MITM)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355004" comment="evolution is earlier than 0:2.0.2-41.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355005" comment="evolution is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355002" comment="evolution-devel is earlier than 0:2.0.2-41.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355003" comment="evolution-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355008" comment="evolution-data-server is earlier than 0:1.0.2-14.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355009" comment="evolution-data-server is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090355006" comment="evolution-data-server-devel is earlier than 0:1.0.2-14.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355007" comment="evolution-data-server-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090358" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0358: evolution security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0358-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0358.html" />
    <description>Evolution is the integrated collection of e-mail, calendaring, contact
management, communications, and personal information management (PIM) tools
for the GNOME desktop environment.

It was discovered that evolution did not properly validate NTLM (NT LAN
Manager) authentication challenge packets. A malicious server using NTLM
authentication could cause evolution to disclose portions of its memory or
crash during user authentication. (CVE-2009-0582)

An integer overflow flaw which could cause heap-based buffer overflow was
found in the Base64 encoding routine used by evolution. This could cause
evolution to crash, or, possibly, execute an arbitrary code when large
untrusted data blocks were Base64-encoded. (CVE-2009-0587)

All users of evolution are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. All running
instances of evolution must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-16" />
        <updated date="2009-03-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0582">CVE-2009-0582</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0587">CVE-2009-0587</cve>
                <bugzilla href="http://bugzilla.redhat.com/487685" id="487685">CVE-2009-0582 evolution-data-server: insufficient checking of NTLM authentication challenge packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488226" id="488226">CVE-2009-0587 evolution-data-server: integer overflow in base64 encoding functions</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090358002" comment="evolution is earlier than 0:1.4.5-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355005" comment="evolution is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090358004" comment="evolution-devel is earlier than 0:1.4.5-25.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090355003" comment="evolution-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090361" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0361: NetworkManager security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0361-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0361.html" />
    <description>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)

A potential denial of service flaw was found in NetworkManager's D-Bus
interface. A local user could leverage this flaw to modify local connection
settings, preventing the system's network connection from functioning
properly. (CVE-2009-0578)

Red Hat would like to thank Ludwig Nussel for reporting these flaws
responsibly.

Users of NetworkManager should upgrade to these updated packages which
contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-25" />
        <updated date="2009-03-25" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0365">CVE-2009-0365</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0578">CVE-2009-0578</cve>
                <bugzilla href="http://bugzilla.redhat.com/487722" id="487722">CVE-2009-0365 NetworkManager: GetSecrets disclosure</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487752" id="487752">CVE-2009-0578 NetworkManager: local users can modify the connection settings</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361002" comment="NetworkManager-glib is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361003" comment="NetworkManager-glib is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361006" comment="NetworkManager-devel is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361007" comment="NetworkManager-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361004" comment="NetworkManager-gnome is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361005" comment="NetworkManager-gnome is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361010" comment="NetworkManager-glib-devel is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361011" comment="NetworkManager-glib-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090361008" comment="NetworkManager is earlier than 1:0.7.0-4.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090361009" comment="NetworkManager is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090362" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0362: NetworkManager security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0362-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0362.html" />
    <description>NetworkManager is a network link manager that attempts to keep a wired or
wireless network connection active at all times.

An information disclosure flaw was found in NetworkManager's D-Bus
interface. A local attacker could leverage this flaw to discover sensitive
information, such as network connection passwords and pre-shared keys.
(CVE-2009-0365)

Red Hat would like to thank Ludwig Nussel for responsibly reporting this
flaw.

NetworkManager users should upgrade to these updated packages, which
contain a backported patch that corrects this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-25" />
        <updated date="2009-03-25" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0365">CVE-2009-0365</cve>
                <bugzilla href="http://bugzilla.redhat.com/487722" id="487722">CVE-2009-0365 NetworkManager: GetSecrets disclosure</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090362002" comment="NetworkManager-gnome is earlier than 0:0.3.1-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090362003" comment="NetworkManager-gnome is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090362004" comment="NetworkManager is earlier than 0:0.3.1-5.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090362005" comment="NetworkManager is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090373" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0373: systemtap security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0373-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0373.html" />
    <description>SystemTap is an instrumentation infrastructure for systems running version
2.6 of the Linux kernel. SystemTap scripts can collect system operations
data, greatly simplifying information gathering. Collected data can then
assist in performance measuring, functional testing, and performance and
function problem diagnosis.

A race condition was discovered in SystemTap that could allow users in the
stapusr group to elevate privileges to that of members of the stapdev group
(and hence root), bypassing directory confinement restrictions and allowing
them to insert arbitrary SystemTap kernel modules. (CVE-2009-0784)

Note: This issue was only exploitable if another SystemTap kernel module
was placed in the "systemtap/" module directory for the currently running
kernel.

Red Hat would like to thank Erik Sjölund for reporting this issue.

SystemTap users should upgrade to these updated packages, which contain a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-26" />
        <updated date="2009-03-26" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0784">CVE-2009-0784</cve>
                <bugzilla href="http://bugzilla.redhat.com/489808" id="489808">CVE-2009-0784 systemtap: race condition leads to privilege escalation</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373010" comment="systemtap is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373011" comment="systemtap is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373006" comment="systemtap-runtime is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373007" comment="systemtap-runtime is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373004" comment="systemtap-testsuite is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373005" comment="systemtap-testsuite is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373008" comment="systemtap-client is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373009" comment="systemtap-client is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373002" comment="systemtap-server is earlier than 0:0.7.2-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373003" comment="systemtap-server is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373017" comment="systemtap-runtime is earlier than 0:0.6.2-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373018" comment="systemtap-runtime is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373015" comment="systemtap-testsuite is earlier than 0:0.6.2-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373016" comment="systemtap-testsuite is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090373013" comment="systemtap is earlier than 0:0.6.2-2.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090373014" comment="systemtap is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090377" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0377: java-1.6.0-openjdk security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0377-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0377.html" />
    <description>These packages provide the OpenJDK 6 Java Runtime Environment and the
OpenJDK 6 Software Development Kit. The Java Runtime Environment (JRE)
contains the software and tools that users need to run applications written
using the Java programming language.

A flaw was found in the way that the Java Virtual Machine (JVM) handled
temporary font files. A malicious applet could use this flaw to use large
amounts of disk space, causing a denial of service. (CVE-2006-2426)

A memory leak flaw was found in LittleCMS (embedded in OpenJDK). An
application using color profiles could use excessive amounts of memory, and
possibly crash after using all available memory, if used to open
specially-crafted images. (CVE-2009-0581)

Multiple integer overflow flaws which could lead to heap-based buffer
overflows, as well as multiple insufficient input validation flaws, were
found in the way LittleCMS handled color profiles. An attacker could use
these flaws to create a specially-crafted image file which could cause a
Java application to crash or, possibly, execute arbitrary code when opened.
(CVE-2009-0723, CVE-2009-0733)

A null pointer dereference flaw was found in LittleCMS. An application
using color profiles could crash while converting a specially-crafted image
file. (CVE-2009-0793)

A flaw in the Java API for XML Web Services (JAX-WS) service endpoint
handling could allow a remote attacker to cause a denial of service on the
server application hosting the JAX-WS service endpoint. (CVE-2009-1101)

A flaw in the way the Java Runtime Environment initialized LDAP connections
could allow a remote, authenticated user to cause a denial of service on
the LDAP service. (CVE-2009-1093)

A flaw in the Java Runtime Environment LDAP client could allow malicious
data from an LDAP server to cause arbitrary code to be loaded and then run
on an LDAP client. (CVE-2009-1094)

Several buffer overflow flaws were found in the Java Runtime Environment
unpack200 functionality. An untrusted applet could extend its privileges,
allowing it to read and write local files, as well as to execute local
applications with the privileges of the user running the applet.
(CVE-2009-1095, CVE-2009-1096)

A flaw in the Java Runtime Environment Virtual Machine code generation
functionality could allow untrusted applets to extend their privileges. An
untrusted applet could extend its privileges, allowing it to read and write
local files, as well as execute local applications with the privileges
of the user running the applet. (CVE-2009-1102)

A buffer overflow flaw was found in the splash screen processing. A remote
attacker could extend privileges to read and write local files, as well as
to execute local applications with the privileges of the user running the
java process. (CVE-2009-1097)

A buffer overflow flaw was found in how GIF images were processed. A remote
attacker could extend privileges to read and write local files, as well as
execute local applications with the privileges of the user running the
java process. (CVE-2009-1098)

Note: The flaws concerning applets in this advisory, CVE-2009-1095,
CVE-2009-1096, and CVE-2009-1102, can only be triggered in
java-1.6.0-openjdk by calling the "appletviewer" application.

All users of java-1.6.0-openjdk are advised to upgrade to these updated
packages, which resolve these issues. All running instances of OpenJDK Java
must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2426">CVE-2006-2426</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0581">CVE-2009-0581</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0723">CVE-2009-0723</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0733">CVE-2009-0733</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0793">CVE-2009-0793</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1093">CVE-2009-1093</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1094">CVE-2009-1094</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1095">CVE-2009-1095</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096">CVE-2009-1096</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1097">CVE-2009-1097</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098">CVE-2009-1098</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1101">CVE-2009-1101</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1102">CVE-2009-1102</cve>
                <bugzilla href="http://bugzilla.redhat.com/492353" id="492353">CVE-2009-0793 lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487512" id="487512">CVE-2009-0733 LittleCms lack of upper-bounds check on sizes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487509" id="487509">CVE-2009-0581 LittleCms memory leak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487508" id="487508">CVE-2009-0723 LittleCms integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490168" id="490168">CVE-2009-1094 OpenJDK  LDAP client remote code execution (6737315)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490174" id="490174">CVE-2009-1097 OpenJDK PNG processing buffer overflow vulnerability (6804996)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490167" id="490167">CVE-2009-1093 OpenJDK remote LDAP Denial-Of-Service (6717680)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490169" id="490169">CVE-2009-1095 CVE-2009-1096 OpenJDK Pack200 Buffer overflow vulnerability (6792554)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490178" id="490178">CVE-2009-1098 OpenJDK GIF processing buffer overflow vulnerability (6804998)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490172" id="490172">CVE-2009-1102 OpenJDK code generation vulnerability (6636360)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/395481" id="395481">CVE-2006-2426 Untrusted applet causes DoS by filling up disk space</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490166" id="490166">CVE-2009-1101 OpenJDK JAX-WS service endpoint remote Denial-of-Service (6630639)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377006" comment="java-1.6.0-openjdk is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377007" comment="java-1.6.0-openjdk is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377010" comment="java-1.6.0-openjdk-src is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377011" comment="java-1.6.0-openjdk-src is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377004" comment="java-1.6.0-openjdk-demo is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377005" comment="java-1.6.0-openjdk-demo is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377002" comment="java-1.6.0-openjdk-devel is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377003" comment="java-1.6.0-openjdk-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090377008" comment="java-1.6.0-openjdk-javadoc is earlier than 1:1.6.0.0-0.30.b09.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090377009" comment="java-1.6.0-openjdk-javadoc is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090382" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0382: libvirt security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0382-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0382.html" />
    <description>libvirt is a C API for managing and interacting with the virtualization
capabilities of Linux and other operating systems. libvirt also provides
tools for remotely managing virtualized systems.

The libvirtd daemon was discovered to not properly check user connection
permissions before performing certain privileged actions, such as
requesting migration of an unprivileged guest domain to another system. A
local user able to establish a read-only connection to libvirtd could use
this flaw to perform actions that should be restricted to read-write
connections. (CVE-2008-5086)

libvirt_proxy, a setuid helper application allowing non-privileged users to
communicate with the hypervisor, was discovered to not properly validate
user requests. Local users could use this flaw to cause a stack-based
buffer overflow in libvirt_proxy, possibly allowing them to run arbitrary
code with root privileges. (CVE-2009-0036)

All users are advised to upgrade to these updated packages, which contain
backported patches which resolve these issues. After installing the update,
libvirtd must be restarted manually (for example, by issuing a
"service libvirtd restart" command) for this change to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-19" />
        <updated date="2009-03-19" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5086">CVE-2008-5086</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0036">CVE-2009-0036</cve>
                <bugzilla href="http://bugzilla.redhat.com/484947" id="484947">CVE-2009-0036 libvirt: libvirt_proxy buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/476560" id="476560">CVE-2008-5086 libvirt: missing checks for read-only connection</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_virtualization</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090382006" comment="libvirt-devel is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090382007" comment="libvirt-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090382002" comment="libvirt is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090382003" comment="libvirt is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090382004" comment="libvirt-python is earlier than 0:0.3.3-14.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090382005" comment="libvirt-python is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090397" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0397: firefox security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0397-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0397.html" />
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A memory corruption flaw was discovered in the way Firefox handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash Firefox or, potentially, execute arbitrary code as the user
running Firefox. (CVE-2009-1169)

A flaw was discovered in the way Firefox handles certain XUL garbage
collection events. A remote attacker could use this flaw to crash Firefox
or, potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1044)

For technical details regarding these flaws, refer to the Mozilla security
advisories. You can find a link to the Mozilla advisories in the References
section of this errata.

Firefox users should upgrade to these updated packages, which resolve these
issues. For Red Hat Enterprise Linux 4, they contain backported patches to
the firefox package. For Red Hat Enterprise Linux 5, they contain
backported patches to the xulrunner packages. After installing the update,
Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-27" />
        <updated date="2009-03-27" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1044">CVE-2009-1044</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1169">CVE-2009-1169</cve>
                <bugzilla href="http://bugzilla.redhat.com/492211" id="492211">CVE-2009-1169 Firefox XSLT memory corruption issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492212" id="492212">CVE-2009-1044 Firefox XUL garbage collection issue (cansecwest pwn2own)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090397006" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090397004" comment="xulrunner is earlier than 0:1.9.0.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090397002" comment="xulrunner-devel is earlier than 0:1.9.0.7-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090397009" comment="firefox is earlier than 0:3.0.7-3.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090398" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0398: seamonkey security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0398-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0398.html" />
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

A memory corruption flaw was discovered in the way SeaMonkey handles XML
files containing an XSLT transform. A remote attacker could use this flaw
to crash SeaMonkey or, potentially, execute arbitrary code as the user
running SeaMonkey. (CVE-2009-1169)

A flaw was discovered in the way SeaMonkey handles certain XUL garbage
collection events. A remote attacker could use this flaw to crash SeaMonkey
or, potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1044)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-27" />
        <updated date="2009-03-27" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1044">CVE-2009-1044</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1169">CVE-2009-1169</cve>
                <bugzilla href="http://bugzilla.redhat.com/492211" id="492211">CVE-2009-1169 Firefox XSLT memory corruption issue</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/492212" id="492212">CVE-2009-1044 Firefox XUL garbage collection issue (cansecwest pwn2own)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398010" comment="seamonkey-nspr is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398014" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398002" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398020" comment="seamonkey-mail is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398004" comment="seamonkey is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398006" comment="seamonkey-devel is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398018" comment="seamonkey-chat is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398016" comment="seamonkey-nss is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398008" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-nss-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398012" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.36.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398027" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398028" comment="seamonkey-mail is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398024" comment="seamonkey is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398023" comment="seamonkey-devel is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398026" comment="seamonkey-chat is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090398025" comment="seamonkey-js-debugger is earlier than 0:1.0.9-40.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090402" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0402: openswan security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0402-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0402.html" />
    <description>Openswan is a free implementation of Internet Protocol Security (IPsec)
and Internet Key Exchange (IKE). IPsec uses strong cryptography to provide
both authentication and encryption services. These services allow you to
build secure tunnels through untrusted networks. Everything passing through
the untrusted network is encrypted by the IPsec gateway machine, and
decrypted by the gateway at the other end of the tunnel. The resulting
tunnel is a virtual private network (VPN).

Gerd v. Egidy discovered a flaw in the Dead Peer Detection (DPD) in
Openswan's pluto IKE daemon. A remote attacker could use a malicious DPD
packet to crash the pluto daemon. (CVE-2009-0790)

It was discovered that Openswan's livetest script created temporary files
in an insecure manner. A local attacker could use this flaw to overwrite
arbitrary files owned by the user running the script. (CVE-2008-4190)

Note: The livetest script is an incomplete feature and was not
automatically executed by any other script distributed with Openswan, or
intended to be used at all, as was documented in its man page. In these
updated packages, the script only prints an informative message and exits
immediately when run.

All users of openswan are advised to upgrade to these updated packages,
which contain backported patches to correct these issues. After installing
this update, the ipsec service will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-03-30" />
        <updated date="2009-03-30" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4190">CVE-2008-4190</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0790">CVE-2009-0790</cve>
                <bugzilla href="http://bugzilla.redhat.com/491895" id="491895">CVE-2009-0790 openswan: ISAKMP DPD remote DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/460425" id="460425">CVE-2008-4190 openswan: Insecure auxiliary /tmp file usage (symlink attack possible)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090402002" comment="openswan is earlier than 0:2.6.14-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090402003" comment="openswan is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090402004" comment="openswan-doc is earlier than 0:2.6.14-1.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090402005" comment="openswan-doc is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090408" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0408: krb5 security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0408-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0408.html" />
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC). The Generic
Security Service Application Program Interface (GSS-API) definition
provides security services to callers (protocols) in a generic fashion. The
Simple and Protected GSS-API Negotiation (SPNEGO) mechanism is used by
GSS-API peers to choose from a common set of security mechanisms.

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)

Multiple input validation flaws were found in the MIT Kerberos GSS-API
library's implementation of the SPNEGO mechanism. A remote attacker could
use these flaws to crash any network service utilizing the MIT Kerberos
GSS-API library to authenticate users or, possibly, leak portions of the
service's memory. (CVE-2009-0844, CVE-2009-0845)

All krb5 users should upgrade to these updated packages, which contain
backported patches to correct these issues. All running services using the
MIT Kerberos libraries must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0844">CVE-2009-0844</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0845">CVE-2009-0845</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846">CVE-2009-0846</cve>
                <bugzilla href="http://bugzilla.redhat.com/490634" id="490634">CVE-2009-0845 krb5: NULL pointer dereference in GSSAPI SPNEGO (MITKRB5-SA-2009-001)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491036" id="491036">CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491033" id="491033">CVE-2009-0844 krb5: buffer over-read in SPNEGO GSS-API mechanism (MITKRB5-SA-2009-001)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408008" comment="krb5-libs is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408009" comment="krb5-libs is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408006" comment="krb5-devel is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408007" comment="krb5-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408002" comment="krb5-server is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408003" comment="krb5-server is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408010" comment="krb5 is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408011" comment="krb5 is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090408004" comment="krb5-workstation is earlier than 0:1.6.1-31.el5_3.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090408005" comment="krb5-workstation is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090409" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0409: krb5 security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0409-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0409.html" />
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer.
(CVE-2009-0846)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running services using the MIT
Kerberos libraries must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846">CVE-2009-0846</cve>
                <bugzilla href="http://bugzilla.redhat.com/491036" id="491036">CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409006" comment="krb5-libs is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409007" comment="krb5-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409008" comment="krb5-devel is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409009" comment="krb5-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409002" comment="krb5-server is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409003" comment="krb5-server is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409010" comment="krb5 is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409011" comment="krb5 is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090409004" comment="krb5-workstation is earlier than 0:1.3.4-60.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409005" comment="krb5-workstation is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090410" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0410: krb5 security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0410-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0410.html" />
    <description>Kerberos is a network authentication system which allows clients and
servers to authenticate to each other using symmetric encryption and a
trusted third party, the Key Distribution Center (KDC).

An input validation flaw was found in the ASN.1 (Abstract Syntax Notation
One) decoder used by MIT Kerberos. A remote attacker could use this flaw to
crash a network service using the MIT Kerberos library, such as kadmind or
krb5kdc, by causing it to dereference or free an uninitialized pointer or,
possibly, execute arbitrary code with the privileges of the user running
the service. (CVE-2009-0846)

All krb5 users should upgrade to these updated packages, which contain a
backported patch to correct this issue. All running services using the MIT
Kerberos libraries must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0846">CVE-2009-0846</cve>
                <bugzilla href="http://bugzilla.redhat.com/491036" id="491036">CVE-2009-0846 krb5: ASN.1 decoder can free uninitialized pointer when decoding an invalid encoding (MITKRB5-SA-2009-002)</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410008" comment="krb5-libs is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409007" comment="krb5-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410006" comment="krb5-devel is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409009" comment="krb5-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410004" comment="krb5-server is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409003" comment="krb5-server is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410010" comment="krb5 is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409011" comment="krb5 is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090410002" comment="krb5-workstation is earlier than 0:1.2.7-70" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090409005" comment="krb5-workstation is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090411" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0411: device-mapper-multipath security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0411-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0411.html" />
    <description>The device-mapper multipath packages provide tools to manage multipath
devices by issuing instructions to the device-mapper multipath kernel
module, and by managing the creation and removal of partitions for
device-mapper devices.

It was discovered that the multipathd daemon set incorrect permissions on
the socket used to communicate with command line clients. An unprivileged,
local user could use this flaw to send commands to multipathd, resulting in
access disruptions to storage devices accessible via multiple paths and,
possibly, file system corruption on these devices. (CVE-2009-0115)

Users of device-mapper-multipath are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. The
multipathd service must be restarted for the changes to take effect.

Important: the version of the multipathd daemon in Red Hat Enterprise Linux
5 has a known issue which may cause a machine to become unresponsive when
the multipathd service is stopped. This issue is tracked in the Bugzilla
bug #494582; a link is provided in the References section of this erratum.
Until this issue is resolved, we recommend restarting the multipathd
service by issuing the following commands in sequence:

	# killall -KILL multipathd

	# service multipathd restart</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-07" />
        <updated date="2009-04-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0115">CVE-2009-0115</cve>
                <bugzilla href="http://bugzilla.redhat.com/493330" id="493330">CVE-2009-0115 device-mapper-multipath: insecure permissions on multipathd.sock</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090411002" comment="kpartx is earlier than 0:0.4.7-23.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411003" comment="kpartx is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090411004" comment="device-mapper-multipath is earlier than 0:0.4.7-23.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411005" comment="device-mapper-multipath is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411007" comment="device-mapper-multipath is earlier than 0:0.4.5-31.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090411008" comment="device-mapper-multipath is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090421" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0421: ghostscript security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0421-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0421.html" />
    <description>Ghostscript is a set of software that provides a PostScript interpreter, a
set of C procedures (the Ghostscript library, which implements the graphics
capabilities in the PostScript language) and an interpreter for Portable
Document Format (PDF) files.

It was discovered that the Red Hat Security Advisory RHSA-2009:0345 did not
address all possible integer overflow flaws in Ghostscript's International
Color Consortium Format library (icclib). Using specially-crafted ICC
profiles, an attacker could create a malicious PostScript or PDF file with
embedded images that could cause Ghostscript to crash or, potentially,
execute arbitrary code when opened. (CVE-2009-0792)

A buffer overflow flaw and multiple missing boundary checks were found in
Ghostscript. An attacker could create a specially-crafted PostScript or PDF
file that could cause Ghostscript to crash or, potentially, execute
arbitrary code when opened. (CVE-2008-6679, CVE-2007-6725, CVE-2009-0196)

Red Hat would like to thank Alin Rad Pop of Secunia Research for
responsibly reporting the CVE-2009-0196 flaw.

Users of ghostscript are advised to upgrade to these updated packages,
which contain backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-14" />
        <updated date="2009-04-14" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6725">CVE-2007-6725</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-6679">CVE-2008-6679</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0196">CVE-2009-0196</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0792">CVE-2009-0792</cve>
                <bugzilla href="http://bugzilla.redhat.com/493379" id="493379">CVE-2009-0196 ghostscript: Missing boundary check in Ghostscript's jbig2dec library</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493445" id="493445">CVE-2008-6679 ghostscript: Buffer overflow in BaseFont writer module for pdfwrite defice</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493442" id="493442">CVE-2007-6725 ghostscript: DoS (crash) in CCITTFax decoding filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491853" id="491853">CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090421004" comment="ghostscript-gtk is earlier than 0:8.15.2-9.4.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090421005" comment="ghostscript-gtk is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090421002" comment="ghostscript is earlier than 0:8.15.2-9.4.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090421003" comment="ghostscript is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090421006" comment="ghostscript-devel is earlier than 0:8.15.2-9.4.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090421007" comment="ghostscript-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090427" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0427: udev security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0427-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0427.html" />
    <description>udev provides a user-space API and implements a dynamic device directory,
providing only the devices present on the system. udev replaces devfs in
order to provide greater hot plug functionality. Netlink is a datagram
oriented service, used to transfer information between kernel modules and
user-space processes.

It was discovered that udev did not properly check the origin of Netlink
messages. A local attacker could use this flaw to gain root privileges via
a crafted Netlink message sent to udev, causing it to create a
world-writable block device file for an existing system block device (for
example, the root file system). (CVE-2009-1185)

Red Hat would like to thank Sebastian Krahmer of the SUSE Security Team for
responsibly reporting this flaw.

Users of udev are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the udevd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1185">CVE-2009-1185</cve>
                <bugzilla href="http://bugzilla.redhat.com/495051" id="495051">CVE-2009-1185 udev: Uncheck origin of NETLINK messages</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090427004" comment="udev is earlier than 0:095-14.20.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090427005" comment="udev is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090427002" comment="libvolume_id is earlier than 0:095-14.20.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090427003" comment="libvolume_id is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090427006" comment="libvolume_id-devel is earlier than 0:095-14.20.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090427007" comment="libvolume_id-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090428" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0428: cups security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0428-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0428.html" />
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

An integer overflow flaw, leading to a heap-based buffer overflow, was
discovered in the Tagged Image File Format (TIFF) decoding routines used by
the CUPS image-converting filters, "imagetops" and "imagetoraster". An
attacker could create a malicious TIFF file that could, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0163)

Red Hat would like to thank Aaron Sigel of the Apple Product Security team
for responsibly reporting this flaw.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163">CVE-2009-0163</cve>
                <bugzilla href="http://bugzilla.redhat.com/490596" id="490596">CVE-2009-0163 cups: Integer overflow in the TIFF image filter</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090428004" comment="cups-devel is earlier than 1:1.1.17-13.3.58" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090428006" comment="cups-libs is earlier than 1:1.1.17-13.3.58" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090428002" comment="cups is earlier than 1:1.1.17-13.3.58" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090429" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0429: cups security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0429-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0429.html" />
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems.

Multiple integer overflow flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0147, CVE-2009-1179)

Multiple buffer overflow flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in the CUPS JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause CUPS to crash or, potentially, execute arbitrary code
as the "lp" user if the file was printed. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
or, potentially, execute arbitrary code as the "lp" user if the file was
printed. (CVE-2009-0800)

An integer overflow flaw, leading to a heap-based buffer overflow, was
discovered in the Tagged Image File Format (TIFF) decoding routines used by
the CUPS image-converting filters, "imagetops" and "imagetoraster". An
attacker could create a malicious TIFF file that could, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0163)

Multiple denial of service flaws were found in the CUPS JBIG2 decoder. An
attacker could create a malicious PDF file that would cause CUPS to crash
when printed. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Aaron Sigel, Braden Thomas and Drew Yao of
the Apple Product Security team, and Will Dormann of the CERT/CC for
responsibly reporting these flaws.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing the
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146">CVE-2009-0146</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147">CVE-2009-0147</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0163">CVE-2009-0163</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166">CVE-2009-0166</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195">CVE-2009-0195</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799">CVE-2009-0799</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800">CVE-2009-0800</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179">CVE-2009-1179</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180">CVE-2009-1180</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181">CVE-2009-1181</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182">CVE-2009-1182</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183">CVE-2009-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/490596" id="490596">CVE-2009-0163 cups: Integer overflow in the TIFF image filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429006" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429004" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429005" comment="cups-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429008" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429009" comment="cups-libs is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429002" comment="cups is earlier than 1:1.3.7-8.el5_3.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429003" comment="cups is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429015" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429013" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090429011" comment="cups is earlier than 1:1.1.22-0.rc1.9.27.el4_7.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090430" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0430: xpdf security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0430-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0430.html" />
    <description>Xpdf is an X Window System based viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in Xpdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause Xpdf to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause Xpdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in Xpdf's JBIG2 decoder. An
attacker could create a malicious PDF that would cause Xpdf to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146">CVE-2009-0146</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147">CVE-2009-0147</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166">CVE-2009-0166</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195">CVE-2009-0195</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799">CVE-2009-0799</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800">CVE-2009-0800</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179">CVE-2009-1179</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180">CVE-2009-1180</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181">CVE-2009-1181</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182">CVE-2009-1182</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183">CVE-2009-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430002" comment="xpdf is earlier than 1:2.02-14.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430005" comment="xpdf is earlier than 1:3.00-20.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090430003" comment="xpdf is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090431" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0431: kdegraphics security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0431-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0431.html" />
    <description>The kdegraphics packages contain applications for the K Desktop
Environment, including KPDF, a viewer for Portable Document Format (PDF)
files.

Multiple integer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in KPDF's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause KPDF to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause KPDF to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in KPDF's JBIG2 decoder. An
attacker could create a malicious PDF that would cause KPDF to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-16" />
        <updated date="2009-04-16" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146">CVE-2009-0146</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147">CVE-2009-0147</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166">CVE-2009-0166</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195">CVE-2009-0195</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799">CVE-2009-0799</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800">CVE-2009-0800</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179">CVE-2009-1179</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180">CVE-2009-1180</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181">CVE-2009-1181</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182">CVE-2009-1182</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183">CVE-2009-1183</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/a:redhat:rhel_productivity</cpe>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431002" comment="kdegraphics is earlier than 7:3.5.4-12.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431003" comment="kdegraphics is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431004" comment="kdegraphics-devel is earlier than 7:3.5.4-12.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431005" comment="kdegraphics-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431007" comment="kdegraphics is earlier than 7:3.3.1-13.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431008" comment="kdegraphics is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090431009" comment="kdegraphics-devel is earlier than 7:3.3.1-13.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090431010" comment="kdegraphics-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090436" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:0436: firefox security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0436-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0436.html" />
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1302, CVE-2009-1303, CVE-2009-1304, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1308, CVE-2009-1309, CVE-2009-1310,
CVE-2009-1312)

A flaw was found in the way Firefox saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.9. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.9, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-21" />
        <updated date="2009-04-21" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652">CVE-2009-0652</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1302">CVE-2009-1302</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303">CVE-2009-1303</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1304">CVE-2009-1304</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305">CVE-2009-1305</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306">CVE-2009-1306</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307">CVE-2009-1307</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1308">CVE-2009-1308</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309">CVE-2009-1309</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1310">CVE-2009-1310</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311">CVE-2009-1311</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312">CVE-2009-1312</cve>
                <bugzilla href="http://bugzilla.redhat.com/486704" id="486704">CVE-2009-0652 firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496252" id="496252">CVE-2009-1302 Firefox 3 Layout engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496253" id="496253">CVE-2009-1303 Firefox 2 and 3 Layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496255" id="496255">CVE-2009-1304 Firefox 3 JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496256" id="496256">CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496262" id="496262">CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496263" id="496263">CVE-2009-1307 Firefox Same-origin violations when Adobe Flash loaded via view-source: protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496266" id="496266">CVE-2009-1308 Firefox XSS hazard using third-party stylesheets and XBL bindings</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496267" id="496267">CVE-2009-1309 Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496270" id="496270">CVE-2009-1310 Firefox Malicious search plugins can inject code into arbitrary sites</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496271" id="496271">CVE-2009-1311 Firefox POST data sent to wrong site when saving web page with embedded frame</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496274" id="496274">CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436002" comment="xulrunner is earlier than 0:1.9.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436006" comment="xulrunner-devel is earlier than 0:1.9.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090436008" comment="firefox is earlier than 0:3.0.9-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090436011" comment="firefox is earlier than 0:3.0.9-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090437" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:0437: seamonkey security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0437-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0437.html" />
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1303, CVE-2009-1305)

Several flaws were found in the way malformed web content was processed. A
web page containing malicious content could execute arbitrary JavaScript in
the context of the site, possibly presenting misleading data to a user, or
stealing sensitive information such as login credentials. (CVE-2009-0652,
CVE-2009-1306, CVE-2009-1307, CVE-2009-1309, CVE-2009-1312)

A flaw was found in the way SeaMonkey saved certain web pages to a local
file. If a user saved the inner frame of a web page containing POST data,
the POST data could be revealed to the inner frame, possibly surrendering
sensitive information such as login credentials. (CVE-2009-1311)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-21" />
        <updated date="2009-04-21" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0652">CVE-2009-0652</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1303">CVE-2009-1303</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1305">CVE-2009-1305</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1306">CVE-2009-1306</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1307">CVE-2009-1307</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1309">CVE-2009-1309</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1311">CVE-2009-1311</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1312">CVE-2009-1312</cve>
                <bugzilla href="http://bugzilla.redhat.com/486704" id="486704">CVE-2009-0652 firefox: does not properly prevent the literal rendering of homoglyph characters in IDN domain names (spoof URLs and conduct phishing attacks)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496253" id="496253">CVE-2009-1303 Firefox 2 and 3 Layout engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496256" id="496256">CVE-2009-1305 Firefox 2 and 3 JavaScript engine crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496262" id="496262">CVE-2009-1306 Firefox jar: scheme ignores the content-disposition: header on the inner URI</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496263" id="496263">CVE-2009-1307 Firefox Same-origin violations when Adobe Flash loaded via view-source: protocol</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496267" id="496267">CVE-2009-1309 Firefox Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496271" id="496271">CVE-2009-1311 Firefox POST data sent to wrong site when saving web page with embedded frame</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496274" id="496274">CVE-2009-1312 Firefox allows Refresh header to redirect to javascript: URIs</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437016" comment="seamonkey-nspr is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437014" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437008" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437018" comment="seamonkey-mail is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437002" comment="seamonkey is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437012" comment="seamonkey-devel is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437020" comment="seamonkey-chat is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437010" comment="seamonkey-nss is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437004" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-nss-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437006" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.37.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437025" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437026" comment="seamonkey-mail is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437023" comment="seamonkey is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437024" comment="seamonkey-devel is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437028" comment="seamonkey-chat is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090437027" comment="seamonkey-js-debugger is earlier than 0:1.0.9-41.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090444" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0444: giflib security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0444-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0444.html" />
    <description>The giflib packages contain a shared library of functions for loading and
saving GIF image files. This library is API and ABI compatible with
libungif, the library that supported uncompressed GIF image files while the
Unisys LZW patent was in effect.

Several flaws were discovered in the way giflib decodes GIF images. An
attacker could create a carefully crafted GIF image that could cause an
application using giflib to crash or, possibly, execute arbitrary code when
opened by a victim. (CVE-2005-2974, CVE-2005-3350)

All users of giflib are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues. All running
applications using giflib must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-22" />
        <updated date="2009-04-22" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2974">CVE-2005-2974</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3350">CVE-2005-3350</cve>
                <bugzilla href="http://bugzilla.redhat.com/494823" id="494823">CVE-2005-3350 giflib/libunfig: memory corruption via a crafted GIF</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494826" id="494826">CVE-2005-2974 giflib/libunfig: NULL pointer dereference crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090444004" comment="giflib-utils is earlier than 0:4.1.3-7.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090444005" comment="giflib-utils is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090444002" comment="giflib is earlier than 0:4.1.3-7.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090444003" comment="giflib is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090444006" comment="giflib-devel is earlier than 0:4.1.3-7.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090444007" comment="giflib-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090449" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0449: firefox security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0449-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0449.html" />
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

A flaw was found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1313)

For technical details regarding this flaw, refer to the Mozilla security
advisory for Firefox 3.0.10. You can find a link to the Mozilla advisories
in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.10, which corrects this issue. After installing the
update, Firefox must be restarted for the change to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-27" />
        <updated date="2009-04-27" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1313">CVE-2009-1313</cve>
                <bugzilla href="http://bugzilla.redhat.com/497447" id="497447">CVE-2009-1313 Firefox crash in nsTextFrame::ClearTextRun()</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449004" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449002" comment="xulrunner is earlier than 0:1.9.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449006" comment="xulrunner-devel is earlier than 0:1.9.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090449008" comment="firefox is earlier than 0:3.0.10-1.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090449011" comment="firefox is earlier than 0:3.0.10-1.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090457" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0457: libwmf security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0457-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0457.html" />
    <description>libwmf is a library for reading and converting Windows Metafile Format
(WMF) vector graphics. libwmf is used by applications such as GIMP and
ImageMagick.

A pointer use-after-free flaw was found in the GD graphics library embedded
in libwmf. An attacker could create a specially-crafted WMF file that would
cause an application using libwmf to crash or, potentially, execute
arbitrary code as the user running the application when opened by a victim.
(CVE-2009-1364)

Note: This flaw is specific to the GD graphics library embedded in libwmf.
It does not affect the GD graphics library from the "gd" packages, or
applications using it.

Red Hat would like to thank Tavis Ormandy of the Google Security Team for
responsibly reporting this flaw.

All users of libwmf are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing the
update, all applications using libwmf must be restarted for the update
to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-30" />
        <updated date="2009-04-30" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1364">CVE-2009-1364</cve>
                <bugzilla href="http://bugzilla.redhat.com/496864" id="496864">EMBARGOED CVE-2009-1364 libwmf: embedded gd use-after-free error</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457002" comment="libwmf is earlier than 0:0.2.8.4-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457003" comment="libwmf is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457004" comment="libwmf-devel is earlier than 0:0.2.8.4-10.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457005" comment="libwmf-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457007" comment="libwmf is earlier than 0:0.2.8.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457008" comment="libwmf is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090457009" comment="libwmf-devel is earlier than 0:0.2.8.3-5.8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090457010" comment="libwmf-devel is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090458" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0458: gpdf security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0458-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0458.html" />
    <description>GPdf is a viewer for Portable Document Format (PDF) files.

Multiple integer overflow flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0147,
CVE-2009-1179)

Multiple buffer overflow flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0146,
CVE-2009-1182)

Multiple flaws were found in GPdf's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause GPdf to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0166, CVE-2009-1180)

Multiple input validation flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause GPdf to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in GPdf's JBIG2 decoder. An
attacker could create a malicious PDF that would cause GPdf to crash when
opened. (CVE-2009-0799, CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to this updated package, which contains
backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-30" />
        <updated date="2009-04-30" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146">CVE-2009-0146</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147">CVE-2009-0147</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166">CVE-2009-0166</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195">CVE-2009-0195</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799">CVE-2009-0799</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800">CVE-2009-0800</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179">CVE-2009-1179</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180">CVE-2009-1180</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181">CVE-2009-1181</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182">CVE-2009-1182</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183">CVE-2009-1183</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606">CVE-2009-3606</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090458002" comment="gpdf is earlier than 0:2.8.2-7.7.2.el4_7.4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090458003" comment="gpdf is signed with Red Hat master key" />
 
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090459" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0459: kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0459-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0459.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* a logic error was found in the do_setlk() function of the Linux kernel
Network File System (NFS) implementation. If a signal interrupted a lock
request, the local POSIX lock was incorrectly created. This could cause a
denial of service on the NFS server if a file descriptor was closed before
its corresponding lock request returned. (CVE-2008-4307, Important)

* a deficiency was found in the Linux kernel system call auditing
implementation on 64-bit systems. This could allow a local, unprivileged
user to circumvent a system call audit configuration, if that configuration
filtered based on the "syscall" number or arguments.
(CVE-2009-0834, Important)

* Chris Evans reported a deficiency in the Linux kernel signals
implementation. The clone() system call permits the caller to indicate the
signal it wants to receive when its child exits. When clone() is called
with the CLONE_PARENT flag, it permits the caller to clone a new child that
shares the same parent as itself, enabling the indicated signal to be sent
to the caller's parent (instead of the caller), even if the caller's parent
has different real and effective user IDs. This could lead to a denial of
service of the parent. (CVE-2009-0028, Moderate)

* the sock_getsockopt() function in the Linux kernel did not properly
initialize a data structure that can be directly returned to user-space
when the getsockopt() function is called with SO_BSDCOMPAT optname set.
This flaw could possibly lead to memory disclosure.
(CVE-2009-0676, Moderate)

Bug fixes:

* a kernel crash may have occurred for Red Hat Enterprise Linux 4.7 guests
if their guest configuration file specified "vif = [ "type=ioemu" ]". This
crash only occurred when starting guests via the "xm create" command.
(BZ#477146)

* a bug in IO-APIC NMI watchdog may have prevented Red Hat Enterprise Linux
4.7 from being installed on HP ProLiant DL580 G5 systems. Hangs during
installation and "NMI received for unknown reason [xx]" errors may have
occurred. (BZ#479184)

* a kernel deadlock on some systems when using netdump through a network
interface that uses the igb driver. (BZ#480579)

* a possible kernel hang in sys_ptrace() on the Itanium® architecture,
possibly triggered by tracing a threaded process with strace. (BZ#484904)

* the RHSA-2008:0665 errata only fixed the known problem with the LSI Logic
LSI53C1030 Ultra320 SCSI controller, for tape devices. Read commands sent
to tape devices may have received incorrect data. This issue may have led
to data corruption. This update includes a fix for all types of devices.
(BZ#487399)

* a missing memory barrier caused a race condition in the AIO subsystem
between the read_events() and aio_complete() functions. This may have
caused a thread in read_events() to sleep indefinitely, possibly causing an
application hang. (BZ#489935)

* due to a lack of synchronization in the NFS client code, modifications
to some pages (for files on an NFS mounted file system) made through a
region of memory mapped by mmap() may be lost if the NFS client invalidates
its page cache for particular files. (BZ#490119)

* a NULL pointer dereference in the megaraid_mbox driver caused a system
crash on some systems. (BZ#493420)

* the ext3_symlink() function in the ext3 file system code used an
illegal __GFP_FS allocation inside some transactions. This may have
resulted in a kernel panic and "Assertion failure" errors. (BZ#493422)

* do_machine_check() cleared all Machine Check Exception (MCE) status
registers, preventing the BIOS from using them to determine the cause of
certain panics and errors. (BZ#494915)

* a bug prevented NMI watchdog from initializing on HP ProLiant DL580 G5
systems. (BZ#497330)

This update contains backported patches to fix these issues. The system
must be rebooted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-04-30" />
        <updated date="2009-04-30" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4307">CVE-2008-4307</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0028">CVE-2009-0028</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0676">CVE-2009-0676</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0834">CVE-2009-0834</cve>
                <bugzilla href="http://bugzilla.redhat.com/456282" id="456282">CVE-2008-4307 Kernel BUG() in locks_remove_flock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/477146" id="477146">RHEL4.7 guest will crash, if creating with only RTL8139 emulation NIC</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479184" id="479184">RHEL 4.7: unknown NMI errors on x86_64 on DL580 G5</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/479932" id="479932">CVE-2009-0028 Linux kernel minor signal handling vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/480579" id="480579">deadlock in igb during netdump</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/484904" id="484904">[RHEL4U4] strace utility can cause system to hang at sys_ptrace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/486305" id="486305">CVE-2009-0676 kernel: memory disclosure in SO_BSDCOMPAT gsopt</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487399" id="487399">[4.7]When SCSI READ Command is issued to tape device, the read data might not be correct for LSI 53C1030 Errata No28.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487990" id="487990">CVE-2009-0834 kernel: x86-64: syscall-audit: 32/64 syscall hole</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489935" id="489935">race in aio_complete() leads to process hang</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490119" id="490119">LTC41974-Pages of a memory mapped NFS file get corrupted.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493420" id="493420">NULL pointer dereference at megaraid_queue_command after a reset</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493422" id="493422">[RHEL4u4] Kernel panic was caused by page_symlink() when kernel has to shrink caches</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497330" id="497330">Enable NMI watchdog on HP DL580 G5</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459002" comment="kernel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014007" comment="kernel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459022" comment="kernel-doc is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014003" comment="kernel-doc is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459004" comment="kernel-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014005" comment="kernel-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459012" comment="kernel-smp-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014019" comment="kernel-smp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459020" comment="kernel-hugemem is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014021" comment="kernel-hugemem is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459014" comment="kernel-largesmp is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014009" comment="kernel-largesmp is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459010" comment="kernel-largesmp-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014011" comment="kernel-largesmp-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459016" comment="kernel-xenU-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014015" comment="kernel-xenU-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459006" comment="kernel-xenU is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014023" comment="kernel-xenU is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459018" comment="kernel-hugemem-devel is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014017" comment="kernel-hugemem-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090459008" comment="kernel-smp is earlier than 0:2.6.9-78.0.22.EL" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090014013" comment="kernel-smp is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090473" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0473: kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0473-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0473.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

This update fixes the following security issues:

* a logic error was found in the do_setlk() function of the Linux kernel
Network File System (NFS) implementation. If a signal interrupted a lock
request, the local POSIX lock was incorrectly created. This could cause a
denial of service on the NFS server if a file descriptor was closed before
its corresponding lock request returned. (CVE-2008-4307, Important)

* a deficiency was found in the Linux kernel system call auditing
implementation on 64-bit systems. This could allow a local, unprivileged
user to circumvent a system call audit configuration, if that configuration
filtered based on the "syscall" number or arguments.
(CVE-2009-0834, Important)

* the exit_notify() function in the Linux kernel did not properly reset the
exit signal if a process executed a set user ID (setuid) application before
exiting. This could allow a local, unprivileged user to elevate their
privileges. (CVE-2009-1337, Important)

* a flaw was found in the ecryptfs_write_metadata_to_contents() function of
the Linux kernel eCryptfs implementation. On systems with a 4096 byte
page-size, this flaw may have caused 4096 bytes of uninitialized kernel
memory to be written into the eCryptfs file headers, leading to an
information leak. Note: Encrypted files created on systems running the
vulnerable version of eCryptfs may contain leaked data in the eCryptfs file
headers. This update does not remove any leaked data. Refer to the
Knowledgebase article in the References section for further information.
(CVE-2009-0787, Moderate)

* the Linux kernel implementation of the Network File System (NFS) did not
properly initialize the file name limit in the nfs_server data structure.
This flaw could possibly lead to a denial of service on a client mounting
an NFS share. (CVE-2009-1336, Moderate)

This update also fixes the following bugs:

* the enic driver (Cisco 10G Ethernet) did not operate under
virtualization. (BZ#472474)

* network interfaces using the IBM eHEA Ethernet device driver could not be
successfully configured under low-memory conditions. (BZ#487035)

* bonding with the "arp_validate=3" option may have prevented fail overs.
(BZ#488064)

* when running under virtualization, the acpi-cpufreq module wrote "Domain
attempted WRMSR" errors to the dmesg log. (BZ#488928)

* NFS clients may have experienced deadlocks during unmount. (BZ#488929)

* the ixgbe driver double counted the number of received bytes and packets.
(BZ#489459)

* the Wacom Intuos3 Lens Cursor device did not work correctly with the
Wacom Intuos3 12x12 tablet. (BZ#489460)

* on the Itanium® architecture, nanosleep() caused commands which used it,
such as sleep and usleep, to sleep for one second more than expected.
(BZ#490434)

* a panic and corruption of slab cache data structures occurred on 64-bit
PowerPC systems when clvmd was running. (BZ#491677)

* the NONSTOP_TSC feature did not perform correctly on the Intel®
microarchitecture (Nehalem) when running in 32-bit mode. (BZ#493356)

* keyboards may not have functioned on IBM eServer System p machines after
a certain point during installation or afterward. (BZ#494293)

* using Device Mapper Multipathing with the qla2xxx driver resulted in
frequent path failures. (BZ#495635)

* if the hypervisor was booted with the dom0_max_vcpus parameter set to
less than the actual number of CPUs in the system, and the cpuspeed service
was started, the hypervisor could crash. (BZ#495931)

* using Openswan to provide an IPsec virtual private network eventually
resulted in a CPU soft lockup and a system crash. (BZ#496044)

* it was possible for posix_locks_deadlock() to enter an infinite loop
(under the BKL), causing a system hang. (BZ#496842)

Users should upgrade to these updated packages, which contain backported
patches to correct these issues. The system must be rebooted for this
update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-07" />
        <updated date="2009-05-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4307">CVE-2008-4307</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0787">CVE-2009-0787</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0834">CVE-2009-0834</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1336">CVE-2009-1336</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1337">CVE-2009-1337</cve>
                <bugzilla href="http://bugzilla.redhat.com/456282" id="456282">CVE-2008-4307 Kernel BUG() in locks_remove_flock</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487035" id="487035">ehea network configuration fails during boot after fsck</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/487990" id="487990">CVE-2009-0834 kernel: x86-64: syscall-audit: 32/64 syscall hole</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488064" id="488064">[RHEL-5.3] ARP packets aren't received by backup slaves breaking arp_validate=3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488928" id="488928">xm dmesg printk spam -- Domain attempted WRMSR 00000000000000e8 from 00000016:3d0e9470 to 00000000:00000000</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/488929" id="488929">Deadlock in flush_workqueue() results in hung nfs clients</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489459" id="489459">[Intel 5.4 bug] ixgbe driver double counts RX byte count</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489460" id="489460">Wacom driver does not with with mouse/lens device on intuos3</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490434" id="490434">[5.3] The nanosleep() syscall sleeps one second longer.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491254" id="491254">CVE-2009-0787 kernel: ecryptfs file header infoleak</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/491677" id="491677">slab corruption with dlm and clvmd on ppc64</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493356" id="493356">[Intel 5.4 FEAT] TSC keeps running in C3+[incremental patch for 5.3.z]</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/493771" id="493771">CVE-2009-1337 kernel: exit_notify: kill the wrong capable(CAP_KILL) check</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494074" id="494074">CVE-2009-1336 kernel: nfsv4 client can be crashed by stating a long filename</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/494293" id="494293">RHEL5-U2 Installation hangs on p-series--7029, 2078</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495635" id="495635">Frequent path failures during I/O on DM multipath devices</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495929" id="495929">[5.3][Xen] APERF/MPERF patch update</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495931" id="495931">[5.3][Xen] dom0 panic when we use dom0_max_vcpus=2.</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496044" id="496044">Running Openswan ipsec vpn server with rhel-5.3 kernel-2.6.18-128.el5 causes crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/496842" id="496842">softlockups due to infinite loops in posix_locks_deadlock</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473004" comment="kernel-headers is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225017" comment="kernel-headers is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473002" comment="kernel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225013" comment="kernel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473024" comment="kernel-doc is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225025" comment="kernel-doc is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473022" comment="kernel-PAE-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225003" comment="kernel-PAE-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473008" comment="kernel-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225015" comment="kernel-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473006" comment="kernel-debug is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225011" comment="kernel-debug is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473018" comment="kernel-kdump is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225019" comment="kernel-kdump is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473012" comment="kernel-xen-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225023" comment="kernel-xen-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473010" comment="kernel-debug-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225005" comment="kernel-debug-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473020" comment="kernel-PAE is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225007" comment="kernel-PAE is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473016" comment="kernel-kdump-devel is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225021" comment="kernel-kdump-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090473014" comment="kernel-xen is earlier than 0:2.6.18-128.1.10.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090225009" comment="kernel-xen is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090474" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0474: acpid security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0474-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0474.html" />
    <description>acpid is a daemon that dispatches ACPI (Advanced Configuration and Power
Interface) events to user-space programs.

Anthony de Almeida Lopes of Outpost24 AB reported a denial of service flaw
in the acpid daemon's error handling. If an attacker could exhaust the
sockets open to acpid, the daemon would enter an infinite loop, consuming
most CPU resources and preventing acpid from communicating with legitimate
processes. (CVE-2009-0798)

Users are advised to upgrade to this updated package, which contains a
backported patch to correct this issue.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-07" />
        <updated date="2009-05-07" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0798">CVE-2009-0798</cve>
                <bugzilla href="http://bugzilla.redhat.com/494443" id="494443">CVE-2009-0798 acpid: too many open files DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474002" comment="acpid is earlier than 0:1.0.4-7.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474003" comment="acpid is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474005" comment="acpid is earlier than 0:1.0.2-4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474006" comment="acpid is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474008" comment="acpid is earlier than 0:1.0.3-2.el4_7.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090474006" comment="acpid is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090476" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0476: pango security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0476-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0476.html" />
    <description>Pango is a library used for the layout and rendering of internationalized
text.

Will Drewry discovered an integer overflow flaw in Pango's
pango_glyph_string_set_size() function. If an attacker is able to pass an
arbitrarily long string to Pango, it may be possible to execute arbitrary
code with the permissions of the application calling Pango. (CVE-2009-1194)

pango and evolution28-pango users are advised to upgrade to these updated
packages, which contain a backported patch to resolve this issue. After
installing this update, you must restart your system or restart the X
server for the update to take effect. Note: Restarting the X server closes
all open applications and logs you out of your session.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-08" />
        <updated date="2009-05-08" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1194">CVE-2009-1194</cve>
                <bugzilla href="http://bugzilla.redhat.com/496887" id="496887">CVE-2009-1194 pango: pango_glyph_string_set_size integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476004" comment="pango-devel is earlier than 0:1.14.9-5.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476005" comment="pango-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476002" comment="pango is earlier than 0:1.14.9-5.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476003" comment="pango is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476009" comment="pango-devel is earlier than 0:1.2.5-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476010" comment="pango-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476007" comment="pango is earlier than 0:1.2.5-8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476008" comment="pango is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476013" comment="pango-devel is earlier than 0:1.6.0-14.4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476010" comment="pango-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476012" comment="pango is earlier than 0:1.6.0-14.4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476008" comment="pango is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476016" comment="evolution28-pango-devel is earlier than 0:1.14.9-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476017" comment="evolution28-pango-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090476014" comment="evolution28-pango is earlier than 0:1.14.9-11.el4_7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090476015" comment="evolution28-pango is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090479" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0479: perl-DBD-Pg security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0479-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0479.html" />
    <description>Perl DBI is a database access Application Programming Interface (API) for
the Perl language. perl-DBD-Pg allows Perl applications to access
PostgreSQL database servers.

A heap-based buffer overflow flaw was discovered in the pg_getline function
implementation. If the pg_getline or getline functions read large,
untrusted records from a database, it could cause an application using
these functions to crash or, possibly, execute arbitrary code.
(CVE-2009-0663)

Note: After installing this update, pg_getline may return more data than
specified by its second argument, as this argument will be ignored. This is
consistent with current upstream behavior. Previously, the length limit
(the second argument) was not enforced, allowing a buffer overflow.

A memory leak flaw was found in the function performing the de-quoting of
BYTEA type values acquired from a database. An attacker able to cause an
application using perl-DBD-Pg to perform a large number of SQL queries
returning BYTEA records, could cause the application to use excessive
amounts of memory or, possibly, crash. (CVE-2009-1341)

All users of perl-DBD-Pg are advised to upgrade to this updated package,
which contains backported patches to fix these issues. Applications using
perl-DBD-Pg must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-13" />
        <updated date="2009-05-13" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0663">CVE-2009-0663</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1341">CVE-2009-1341</cve>
                <bugzilla href="http://bugzilla.redhat.com/497367" id="497367">CVE-2009-0663 perl-DBD-Pg: pg_getline buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497503" id="497503">CVE-2009-1341 perl-DBD-Pg: dequote_bytea memory leak</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090479002" comment="perl-DBD-Pg is earlier than 0:1.49-2.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090479003" comment="perl-DBD-Pg is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20090480" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:0480: poppler security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:0480-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-0480.html" />
    <description>Poppler is a Portable Document Format (PDF) rendering library, used by
applications such as Evince.

Multiple integer overflow flaws were found in poppler. An attacker could
create a malicious PDF file that would cause applications that use poppler
(such as Evince) to crash or, potentially, execute arbitrary code when
opened. (CVE-2009-0147, CVE-2009-1179, CVE-2009-1187, CVE-2009-1188)

Multiple buffer overflow flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (CVE-2009-0146, CVE-2009-1182)

Multiple flaws were found in poppler's JBIG2 decoder that could lead to the
freeing of arbitrary memory. An attacker could create a malicious PDF file
that would cause applications that use poppler (such as Evince) to crash
or, potentially, execute arbitrary code when opened. (CVE-2009-0166,
CVE-2009-1180)

Multiple input validation flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash or, potentially, execute
arbitrary code when opened. (CVE-2009-0800)

Multiple denial of service flaws were found in poppler's JBIG2 decoder. An
attacker could create a malicious PDF file that would cause applications
that use poppler (such as Evince) to crash when opened. (CVE-2009-0799,
CVE-2009-1181, CVE-2009-1183)

Red Hat would like to thank Braden Thomas and Drew Yao of the Apple Product
Security team, and Will Dormann of the CERT/CC for responsibly reporting
these flaws.

Users are advised to upgrade to these updated packages, which contain
backported patches to resolve these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-13" />
        <updated date="2009-05-13" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0146">CVE-2009-0146</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0147">CVE-2009-0147</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0166">CVE-2009-0166</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0195">CVE-2009-0195</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791">CVE-2009-0791</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0799">CVE-2009-0799</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0800">CVE-2009-0800</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1179">CVE-2009-1179</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1180">CVE-2009-1180</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1181">CVE-2009-1181</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1182">CVE-2009-1182</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1183">CVE-2009-1183</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1187">CVE-2009-1187</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1188">CVE-2009-1188</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3604">CVE-2009-3604</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3606">CVE-2009-3606</cve>
                <bugzilla href="http://bugzilla.redhat.com/490612" id="490612">CVE-2009-0146 xpdf: Multiple buffer overflows in JBIG2 decoder (setBitmap, readSymbolDictSeg) (CVE-2009-0195)</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490614" id="490614">CVE-2009-0147 xpdf: Multiple integer overflows in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490625" id="490625">CVE-2009-0166 xpdf: Freeing of potentially uninitialized memory in JBIG2 decoder</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495886" id="495886">CVE-2009-0799 PDF JBIG2 decoder OOB read</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495887" id="495887">CVE-2009-0800 PDF JBIG2 multiple input validation flaws</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495889" id="495889">CVE-2009-1179 PDF JBIG2 integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495892" id="495892">CVE-2009-1180 PDF JBIG2 invalid free()</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495894" id="495894">CVE-2009-1181 PDF JBIG2 NULL dereference</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495896" id="495896">CVE-2009-1182 PDF JBIG2 MMR decoder buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495899" id="495899">CVE-2009-1183 PDF JBIG2 MMR infinite loop DoS</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495906" id="495906">CVE-2009-1187 poppler CairoOutputDev integer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495907" id="495907">CVE-2009-1188 xpdf/poppler: SplashBitmap integer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
 
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090480006" comment="poppler-utils is earlier than 0:0.5.4-4.4.el5_3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480007" comment="poppler-utils is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090480002" comment="poppler is earlier than 0:0.5.4-4.4.el5_3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480003" comment="poppler is signed with Red Hat redhatrelease key" />
 
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090480004" comment="poppler-devel is earlier than 0:0.5.4-4.4.el5_3.9" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090480005" comment="poppler-devel is signed with Red Hat redhatrelease key" />
 
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091036" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1036: ipsec-tools security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1036-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1036.html" />
    <description>The ipsec-tools package is used in conjunction with the IPsec functionality
in the Linux kernel and includes racoon, an IKEv1 keying daemon.

A denial of service flaw was found in the ipsec-tools racoon daemon. An
unauthenticated, remote attacker could trigger a NULL pointer dereference
that could cause the racoon daemon to crash. (CVE-2009-1574)

Multiple memory leak flaws were found in the ipsec-tools racoon daemon. If
a remote attacker is able to make multiple connection attempts to the
racoon daemon, it was possible to cause the racoon daemon to consume all
available memory. (CVE-2009-1632)

Users of ipsec-tools should upgrade to this updated package, which contains
backported patches to correct these issues. Users must restart the racoon
daemon for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1574">CVE-2009-1574</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1632">CVE-2009-1632</cve>
                <bugzilla href="http://bugzilla.redhat.com/497990" id="497990">CVE-2009-1574 ipsec-tools: racoon NULL dereference in fragmentation code</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500886" id="500886">CVE-2009-1632 ipsec-tools: multiple memory leaks fixed in 0.7.2</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091036002" comment="ipsec-tools is earlier than 0:0.6.5-13.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091036003" comment="ipsec-tools is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091039" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1039: ntp security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1039-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1039.html" />
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A buffer overflow flaw was discovered in the ntpd daemon's NTPv4
authentication code. If ntpd was configured to use public key cryptography
for NTP packet authentication, a remote attacker could use this flaw to
send a specially-crafted request packet that could crash ntpd.
(CVE-2009-1252)

Note: NTP authentication is not enabled by default.

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159">CVE-2009-0159</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252">CVE-2009-1252</cve>
                <bugzilla href="http://bugzilla.redhat.com/490617" id="490617">CVE-2009-0159 ntp: buffer overflow in ntpq</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499694" id="499694">CVE-2009-1252 ntp: remote arbitrary code execution vulnerability if autokeys is enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091039002" comment="ntp is earlier than 0:4.2.2p1-9.el5_3.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046003" comment="ntp is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091040" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:1040: ntp security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1040-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1040.html" />
    <description>The Network Time Protocol (NTP) is used to synchronize a computer's time
with a referenced time source.

A buffer overflow flaw was discovered in the ntpd daemon's NTPv4
authentication code. If ntpd was configured to use public key cryptography
for NTP packet authentication, a remote attacker could use this flaw to
send a specially-crafted request packet that could crash ntpd or,
potentially, execute arbitrary code with the privileges of the "ntp" user.
(CVE-2009-1252)

Note: NTP authentication is not enabled by default.

A buffer overflow flaw was found in the ntpq diagnostic command. A
malicious, remote server could send a specially-crafted reply to an ntpq
request that could crash ntpq or, potentially, execute arbitrary code with
the privileges of the user running the ntpq command. (CVE-2009-0159)

All ntp users are advised to upgrade to this updated package, which
contains backported patches to resolve these issues. After installing the
update, the ntpd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-18" />
        <updated date="2009-05-18" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0159">CVE-2009-0159</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1252">CVE-2009-1252</cve>
                <bugzilla href="http://bugzilla.redhat.com/490617" id="490617">CVE-2009-0159 ntp: buffer overflow in ntpq</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499694" id="499694">CVE-2009-1252 ntp: remote arbitrary code execution vulnerability if autokeys is enabled</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091040002" comment="ntp is earlier than 0:4.2.0.a.20040617-8.el4_7.2" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090046006" comment="ntp is signed with Red Hat master key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091059" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:1059: pidgin security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1059-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1059.html" />
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A buffer overflow flaw was found in the way Pidgin initiates file transfers
when using the Extensible Messaging and Presence Protocol (XMPP). If a
Pidgin client initiates a file transfer, and the remote target sends a
malformed response, it could cause Pidgin to crash or, potentially, execute
arbitrary code with the permissions of the user running Pidgin. This flaw
only affects accounts using XMPP, such as Jabber and Google Talk.
(CVE-2009-1373)

It was discovered that on 32-bit platforms, the Red Hat Security Advisory
RHSA-2008:0584 provided an incomplete fix for the integer overflow flaw
affecting Pidgin's MSN protocol handler. If a Pidgin client receives a
specially-crafted MSN message, it may be possible to execute arbitrary code
with the permissions of the user running Pidgin. (CVE-2009-1376)

Note: By default, when using an MSN account, only users on your buddy list
can send you messages. This prevents arbitrary MSN users from exploiting
this flaw.

All Pidgin users should upgrade to this update package, which contains
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1373">CVE-2009-1373</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1376">CVE-2009-1376</cve>
                <bugzilla href="http://bugzilla.redhat.com/500488" id="500488">CVE-2009-1373 pidgin file transfer buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500493" id="500493">CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059002" comment="pidgin is earlier than 0:1.5.1-3.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091060" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:1060: pidgin security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1060-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1060.html" />
    <description>Pidgin is an instant messaging program which can log in to multiple
accounts on multiple instant messaging networks simultaneously.

A buffer overflow flaw was found in the way Pidgin initiates file transfers
when using the Extensible Messaging and Presence Protocol (XMPP). If a
Pidgin client initiates a file transfer, and the remote target sends a
malformed response, it could cause Pidgin to crash or, potentially, execute
arbitrary code with the permissions of the user running Pidgin. This flaw
only affects accounts using XMPP, such as Jabber and Google Talk.
(CVE-2009-1373)

A denial of service flaw was found in Pidgin's QQ protocol decryption
handler. When the QQ protocol decrypts packet information, heap data can be
overwritten, possibly causing Pidgin to crash. (CVE-2009-1374)

A flaw was found in the way Pidgin's PurpleCircBuffer object is expanded.
If the buffer is full when more data arrives, the data stored in this
buffer becomes corrupted. This corrupted data could result in confusing or
misleading data being presented to the user, or possibly crash Pidgin.
(CVE-2009-1375)

It was discovered that on 32-bit platforms, the Red Hat Security Advisory
RHSA-2008:0584 provided an incomplete fix for the integer overflow flaw
affecting Pidgin's MSN protocol handler. If a Pidgin client receives a
specially-crafted MSN message, it may be possible to execute arbitrary code
with the permissions of the user running Pidgin. (CVE-2009-1376)

Note: By default, when using an MSN account, only users on your buddy list
can send you messages. This prevents arbitrary MSN users from exploiting
this flaw.

All Pidgin users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Pidgin must be restarted for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1373">CVE-2009-1373</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1374">CVE-2009-1374</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1375">CVE-2009-1375</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1376">CVE-2009-1376</cve>
                <bugzilla href="http://bugzilla.redhat.com/500488" id="500488">CVE-2009-1373 pidgin file transfer buffer overflow</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500490" id="500490">CVE-2009-1374 pidgin DoS when decrypting qq packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500491" id="500491">CVE-2009-1375 pidgin PurpleCircBuffer corruption</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500493" id="500493">CVE-2009-1376 pidgin incomplete fix for CVE-2008-2927</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060016" comment="finch is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060017" comment="finch is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060010" comment="libpurple-perl is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060011" comment="libpurple-perl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060008" comment="libpurple is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060009" comment="libpurple is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060002" comment="pidgin is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060003" comment="pidgin is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060018" comment="pidgin-devel is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060019" comment="pidgin-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060012" comment="pidgin-perl is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060013" comment="pidgin-perl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060006" comment="finch-devel is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060007" comment="finch-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060004" comment="libpurple-devel is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060005" comment="libpurple-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060014" comment="libpurple-tcl is earlier than 0:2.5.5-3.el5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060015" comment="libpurple-tcl is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060037" comment="libpurple-perl is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060038" comment="libpurple-perl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060031" comment="finch is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060032" comment="finch is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060029" comment="libpurple is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060030" comment="libpurple is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060021" comment="pidgin is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091059003" comment="pidgin is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060035" comment="pidgin-devel is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060036" comment="pidgin-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060033" comment="finch-devel is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060034" comment="finch-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060027" comment="pidgin-perl is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060028" comment="pidgin-perl is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060025" comment="libpurple-devel is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060026" comment="libpurple-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091060023" comment="libpurple-tcl is earlier than 0:2.5.5-2.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091060024" comment="libpurple-tcl is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091061" version="303" class="patch">
      <metadata>
        <title>RHSA-2009:1061: freetype security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1061-02" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1061.html" />
    <description>FreeType is a free, high-quality, portable font engine that can open and
manage font files. It also loads, hints, and renders individual glyphs
efficiently. These packages provide the FreeType 2 font engine.

Tavis Ormandy of the Google Security Team discovered several integer
overflow flaws in the FreeType 2 font engine. If a user loaded a
carefully-crafted font file with an application linked against FreeType 2,
it could cause the application to crash or, possibly, execute arbitrary
code with the privileges of the user running the application.
(CVE-2009-0946)

Users are advised to upgrade to these updated packages, which contain a
backported patch to correct these issues. The X server must be restarted
(log out, then log back in) for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-22" />
        <updated date="2009-05-22" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0946">CVE-2009-0946</cve>
                <bugzilla href="http://bugzilla.redhat.com/491384" id="491384">CVE-2009-0946 freetype: multiple integer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091061002" comment="freetype is earlier than 0:2.2.1-21.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091061003" comment="freetype is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091061006" comment="freetype-demos is earlier than 0:2.2.1-21.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091061007" comment="freetype-demos is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091061004" comment="freetype-devel is earlier than 0:2.2.1-21.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091061005" comment="freetype-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091066" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1066: squirrelmail security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1066-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1066.html" />
    <description>SquirrelMail is a standards-based webmail package written in PHP.

A server-side code injection flaw was found in the SquirrelMail
"map_yp_alias" function. If SquirrelMail was configured to retrieve a
user's IMAP server address from a Network Information Service (NIS) server
via the "map_yp_alias" function, an unauthenticated, remote attacker using
a specially-crafted username could use this flaw to execute arbitrary code
with the privileges of the web server. (CVE-2009-1579)

Multiple cross-site scripting (XSS) flaws were found in SquirrelMail. An
attacker could construct a carefully crafted URL, which once visited by an 
unsuspecting user, could cause the user's web browser to execute malicious
script in the context of the visited SquirrelMail web page. (CVE-2009-1578)

It was discovered that SquirrelMail did not properly sanitize Cascading
Style Sheets (CSS) directives used in HTML mail. A remote attacker could
send a specially-crafted email that could place mail content above
SquirrelMail's controls, possibly allowing phishing and cross-site
scripting attacks. (CVE-2009-1581)

Users of squirrelmail should upgrade to this updated package, which
contains backported patches to correct these issues.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-26" />
        <updated date="2009-05-26" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1578">CVE-2009-1578</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1579">CVE-2009-1579</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1581">CVE-2009-1581</cve>
                <bugzilla href="http://bugzilla.redhat.com/500356" id="500356">CVE-2009-1581 SquirrelMail: CSS positioning vulnerability</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500360" id="500360">CVE-2009-1579 SquirrelMail: Server-side code injection in map_yp_alias username map</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500363" id="500363">CVE-2009-1578 SquirrelMail: Multiple cross site scripting issues</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091066002" comment="squirrelmail is earlier than 0:1.4.8-5.el5_3.7" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010003" comment="squirrelmail is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091066005" comment="squirrelmail is earlier than 0:1.4.8-13.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091066008" comment="squirrelmail is earlier than 0:1.4.8-5.el4_8.5" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090010006" comment="squirrelmail is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091075" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1075: httpd security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1075-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1075.html" />
    <description>The Apache HTTP Server is a popular and freely-available Web server.

A flaw was found in the handling of compression structures between mod_ssl
and OpenSSL. If too many connections were opened in a short period of time,
all system memory and swap space would be consumed by httpd, negatively
impacting other processes, or causing a system crash. (CVE-2008-1678)

Note: The CVE-2008-1678 issue did not affect Red Hat Enterprise Linux 5
prior to 5.3. The problem was introduced via the RHBA-2009:0181 errata in
Red Hat Enterprise Linux 5.3, which upgraded OpenSSL to the newer 0.9.8e
version.

A flaw was found in the handling of the "Options" and "AllowOverride"
directives. In configurations using the "AllowOverride" directive with
certain "Options=" arguments, local users were not restricted from
executing commands from a Server-Side-Include script as intended.
(CVE-2009-1195)

All httpd users should upgrade to these updated packages, which contain
backported patches to resolve these issues. Users must restart httpd for
this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-05-27" />
        <updated date="2009-05-27" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1678">CVE-2008-1678</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1195">CVE-2009-1195</cve>
                <bugzilla href="http://bugzilla.redhat.com/447268" id="447268">CVE-2008-1678 httpd: mod_ssl per-connection memory leak for connections with zlib compression</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/489436" id="489436">CVE-2009-1195 AllowOverride Options=IncludesNoExec allows Options Includes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497077" id="497077">memory leak in httpd</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075004" comment="httpd-manual is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075005" comment="httpd-manual is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075006" comment="httpd-devel is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075007" comment="httpd-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075008" comment="mod_ssl is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075009" comment="mod_ssl is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091075002" comment="httpd is earlier than 0:2.2.3-22.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091075003" comment="httpd is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091082" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1082: cups security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1082-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1082.html" />
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. 

A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)

Red Hat would like to thank Anibal Sacco from Core Security Technologies
for reporting this issue.

Users of cups are advised to upgrade to these updated packages, which
contain a backported patch to correct this issue. After installing this
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-03" />
        <updated date="2009-06-03" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0949">CVE-2009-0949</cve>
                <bugzilla href="http://bugzilla.redhat.com/500972" id="500972">CVE-2009-0949 cups: IPP_TAG_UNSUPPORTED handling NULL pointer dereference DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082008" comment="cups-lpd is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429007" comment="cups-lpd is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082006" comment="cups-devel is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429005" comment="cups-devel is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082004" comment="cups-libs is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429009" comment="cups-libs is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091082002" comment="cups is earlier than 1:1.3.7-8.el5_3.6" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090429003" comment="cups is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091083" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1083: cups security update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1083-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1083.html" />
    <description>The Common UNIX® Printing System (CUPS) provides a portable printing layer
for UNIX operating systems. The Internet Printing Protocol (IPP) allows
users to print and manage printing-related tasks over a network. The CUPS
"pdftops" filter converts Portable Document Format (PDF) files to
PostScript. "pdftops" is based on Xpdf and the CUPS imaging library.

A NULL pointer dereference flaw was found in the CUPS IPP routine, used for
processing incoming IPP requests for the CUPS scheduler. An attacker could
use this flaw to send specially-crafted IPP requests that would crash the
cupsd daemon. (CVE-2009-0949)

A use-after-free flaw was found in the CUPS scheduler directory services
routine, used to process data about available printers and printer classes.
An attacker could use this flaw to cause a denial of service (cupsd daemon
stop or crash). (CVE-2009-1196)

Multiple integer overflows flaws, leading to heap-based buffer overflows,
were found in the CUPS "pdftops" filter. An attacker could create a
malicious PDF file that would cause "pdftops" to crash or, potentially,
execute arbitrary code as the "lp" user if the file was printed.
(CVE-2009-0791)

Red Hat would like to thank Anibal Sacco from Core Security Technologies
for reporting the CVE-2009-0949 flaw, and Swen van Brussel for reporting
the CVE-2009-1196 flaw.

Users of cups are advised to upgrade to these updated packages, which
contain backported patches to correct these issues. After installing this
update, the cupsd daemon will be restarted automatically.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Important</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-03" />
        <updated date="2009-06-03" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0791">CVE-2009-0791</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0949">CVE-2009-0949</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1196">CVE-2009-1196</cve>
                <bugzilla href="http://bugzilla.redhat.com/491840" id="491840">CVE-2009-0791 cups: Multiple integer overflows in the CUPS "pdftops" filter</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/497135" id="497135">CVE-2009-1196 cups: DoS (stop, crash) by  renewing CUPS browse packets</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/500972" id="500972">CVE-2009-0949 cups: IPP_TAG_UNSUPPORTED handling NULL pointer dereference DoS</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083006" comment="cups-devel is earlier than 1:1.1.17-13.3.62" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083004" comment="cups-libs is earlier than 1:1.1.17-13.3.62" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083002" comment="cups is earlier than 1:1.1.17-13.3.62" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083010" comment="cups-devel is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308007" comment="cups-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083011" comment="cups-libs is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308005" comment="cups-libs is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091083009" comment="cups is earlier than 1:1.1.22-0.rc1.9.32.el4_8.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090308003" comment="cups is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091095" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1095: firefox security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1095-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1095.html" />
    <description>Mozilla Firefox is an open source Web browser. XULRunner provides the XUL
Runtime environment for Mozilla Firefox.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause Firefox to crash or,
potentially, execute arbitrary code as the user running Firefox.
(CVE-2009-1392, CVE-2009-1832, CVE-2009-1833, CVE-2009-1837, CVE-2009-1838,
CVE-2009-1841)

Multiple flaws were found in the processing of malformed, local file
content. If a user loaded malicious, local content via the file:// URL, it
was possible for that content to access other local data. (CVE-2009-1835,
CVE-2009-1839)

A script, privilege elevation flaw was found in the way Firefox loaded XML
User Interface Language (XUL) scripts. Firefox and certain add-ons could
load malicious content when certain policy checks did not happen.
(CVE-2009-1840)

A flaw was found in the way Firefox displayed certain Unicode characters in
International Domain Names (IDN). If an IDN contained invalid characters,
they may have been displayed as spaces, making it appear to the user that
they were visiting a trusted site. (CVE-2009-1834)

A flaw was found in the way Firefox handled error responses returned from
proxy servers. If an attacker is able to conduct a man-in-the-middle attack
against a Firefox instance that is using a proxy server, they may be able
to steal sensitive information from the site the user is visiting.
(CVE-2009-1836)

For technical details regarding these flaws, refer to the Mozilla security
advisories for Firefox 3.0.11. You can find a link to the Mozilla
advisories in the References section of this errata.

All Firefox users should upgrade to these updated packages, which contain
Firefox version 3.0.11, which corrects these issues. After installing the
update, Firefox must be restarted for the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-11" />
        <updated date="2009-06-11" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392">CVE-2009-1392</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1832">CVE-2009-1832</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833">CVE-2009-1833</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1834">CVE-2009-1834</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835">CVE-2009-1835</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1836">CVE-2009-1836</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1837">CVE-2009-1837</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838">CVE-2009-1838</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1839">CVE-2009-1839</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1840">CVE-2009-1840</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841">CVE-2009-1841</cve>
                <bugzilla href="http://bugzilla.redhat.com/488570" id="488570">frequent firefox crashes against clearspace</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503568" id="503568">CVE-2009-1392 Firefox browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503569" id="503569">CVE-2009-1832 Firefox double frame construction flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503570" id="503570">CVE-2009-1833 Firefox JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503573" id="503573">CVE-2009-1834 Firefox URL spoofing with invalid unicode characters</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503576" id="503576">CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503578" id="503578">CVE-2009-1836 Firefox SSL tampering via non-200 responses to proxy CONNECT requests</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503579" id="503579">CVE-2009-1837 Firefox Race condition while accessing the private data of a NPObject JS wrapper class object</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503580" id="503580">CVE-2009-1838 Firefox arbitrary code execution flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503581" id="503581">CVE-2009-1839 Firefox information disclosure flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503582" id="503582">CVE-2009-1840 Firefox XUL scripts skip some security checks</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503583" id="503583">CVE-2009-1841 Firefox JavaScript arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095002" comment="firefox is earlier than 0:3.0.11-2.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256009" comment="firefox is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095006" comment="xulrunner-devel-unstable is earlier than 0:1.9.0.11-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256005" comment="xulrunner-devel-unstable is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095004" comment="xulrunner is earlier than 0:1.9.0.11-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256003" comment="xulrunner is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091095008" comment="xulrunner-devel is earlier than 0:1.9.0.11-3.el5_3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256007" comment="xulrunner-devel is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091095011" comment="firefox is earlier than 0:3.0.11-4.el4" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090256020" comment="firefox is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091096" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1096: seamonkey security update (Critical)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1096-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1096.html" />
    <description>SeaMonkey is an open source Web browser, email and newsgroup client, IRC
chat client, and HTML editor.

Several flaws were found in the processing of malformed web content. A web
page containing malicious content could cause SeaMonkey to crash or,
potentially, execute arbitrary code as the user running SeaMonkey.
(CVE-2009-1392, CVE-2009-1833, CVE-2009-1838, CVE-2009-1841)

A flaw was found in the processing of malformed, local file content. If a
user loaded malicious, local content via the file:// URL, it was possible
for that content to access other local data. (CVE-2009-1835)

All SeaMonkey users should upgrade to these updated packages, which correct
these issues. After installing the update, SeaMonkey must be restarted for
the changes to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Critical</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-11" />
        <updated date="2009-06-11" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1392">CVE-2009-1392</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1833">CVE-2009-1833</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1835">CVE-2009-1835</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1838">CVE-2009-1838</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1841">CVE-2009-1841</cve>
                <bugzilla href="http://bugzilla.redhat.com/503568" id="503568">CVE-2009-1392 Firefox browser engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503570" id="503570">CVE-2009-1833 Firefox JavaScript engine crashes</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503576" id="503576">CVE-2009-1835 Firefox Arbitrary domain cookie access by local file: resources</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503580" id="503580">CVE-2009-1838 Firefox arbitrary code execution flaw</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/503583" id="503583">CVE-2009-1841 Firefox JavaScript arbitrary code execution</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096008" comment="seamonkey-nspr is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257007" comment="seamonkey-nspr is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096020" comment="seamonkey-nspr-devel is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257019" comment="seamonkey-nspr-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096014" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096004" comment="seamonkey-mail is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096002" comment="seamonkey is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096010" comment="seamonkey-devel is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096016" comment="seamonkey-nss-devel is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257011" comment="seamonkey-nss-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096012" comment="seamonkey-nss is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257021" comment="seamonkey-nss is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096006" comment="seamonkey-chat is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096018" comment="seamonkey-js-debugger is earlier than 0:1.0.9-0.38.el3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096026" comment="seamonkey-dom-inspector is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257009" comment="seamonkey-dom-inspector is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096027" comment="seamonkey-mail is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257013" comment="seamonkey-mail is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096023" comment="seamonkey is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257005" comment="seamonkey is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096024" comment="seamonkey-devel is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257015" comment="seamonkey-devel is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096028" comment="seamonkey-chat is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257017" comment="seamonkey-chat is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091096025" comment="seamonkey-js-debugger is earlier than 0:1.0.9-43.el4_8" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090257003" comment="seamonkey-js-debugger is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091100" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1100: wireshark security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 3</platform>
             <platform>Red Hat Enterprise Linux 5</platform>
             <platform>Red Hat Enterprise Linux 4</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1100-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1100.html" />
    <description>Wireshark is a program for monitoring network traffic. Wireshark was
previously known as Ethereal.

A format string flaw was found in Wireshark. If Wireshark read a malformed
packet off a network or opened a malicious dump file, it could crash or,
possibly, execute arbitrary code as the user running Wireshark. (CVE-2009-1210)

Several denial of service flaws were found in Wireshark. Wireshark could
crash or stop responding if it read a malformed packet off a network, or
opened a malicious dump file. (CVE-2009-1268, CVE-2009-1269, CVE-2009-1829)

Users of wireshark should upgrade to these updated packages, which contain
Wireshark version 1.0.8, and resolve these issues. All running instances of
Wireshark must be restarted for the update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-15" />
        <updated date="2009-06-15" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1210">CVE-2009-1210</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1268">CVE-2009-1268</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1269">CVE-2009-1269</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1829">CVE-2009-1829</cve>
                <bugzilla href="http://bugzilla.redhat.com/493973" id="493973">CVE-2009-1210 wireshark: format string in PROFINET dissector</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495119" id="495119">CVE-2009-1268 Wireshark CHAP dissector crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/495121" id="495121">CVE-2009-1269 Wireshark Tektronix .rf5 file crash</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/501929" id="501929">CVE-2009-1829 wireshark: PCNFSD dissector crash</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100002" comment="wireshark is earlier than 0:1.0.8-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313005" comment="wireshark is signed with Red Hat redhatrelease key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100004" comment="wireshark-gnome is earlier than 0:1.0.8-1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313003" comment="wireshark-gnome is signed with Red Hat redhatrelease key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100007" comment="wireshark is earlier than 0:1.0.8-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100009" comment="wireshark-gnome is earlier than 0:1.0.8-EL3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" />
 <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100012" comment="wireshark is earlier than 0:1.0.8-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313008" comment="wireshark is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20091100013" comment="wireshark-gnome is earlier than 0:1.0.8-1.el4_8.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20090313010" comment="wireshark-gnome is signed with Red Hat master key" />
  
</criteria>

</criteria>

</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091101" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1101: cscope security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 4</platform>
             <platform>Red Hat Enterprise Linux 3</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1101-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1101.html" />
    <description>cscope is a mature, ncurses-based, C source-code tree browsing tool.

Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2006-4262, CVE-2009-0148, CVE-2009-1577)

All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-15" />
        <updated date="2009-06-15" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2541">CVE-2004-2541</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4262">CVE-2006-4262</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0148">CVE-2009-0148</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1577">CVE-2009-1577</cve>
                <bugzilla href="http://bugzilla.redhat.com/203645" id="203645">CVE-2006-4262 cscope: multiple buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/490667" id="490667">CVE-2004-2541, CVE-2009-0148 cscope: multiple buffer overflows</bugzilla>
            <bugzilla href="http://bugzilla.redhat.com/499174" id="499174">CVE-2009-1577 cscope: putstring buffer overflow</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="OR">
  
 <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004010" comment="Red Hat Enterprise Linux 3 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101002" comment="cscope is earlier than 0:15.5-16.RHEL3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101003" comment="cscope is signed with Red Hat master key" />
  
</criteria>
<criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090004019" comment="Red Hat Enterprise Linux 4 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101005" comment="cscope is earlier than 0:15.5-10.RHEL4.3" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091101003" comment="cscope is signed with Red Hat master key" />
  
</criteria>

</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091102" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1102: cscope security update (Moderate)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1102-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1102.html" />
    <description>cscope is a mature, ncurses-based, C source-code tree browsing tool.

Multiple buffer overflow flaws were found in cscope. An attacker could
create a specially crafted source code file that could cause cscope to
crash or, possibly, execute arbitrary code when browsed with cscope.
(CVE-2004-2541, CVE-2009-0148)

All users of cscope are advised to upgrade to this updated package, which
contains backported patches to fix these issues. All running instances of
cscope must be restarted for this update to take effect.</description>

<!-- ~~~~~~~~~~~~~~~~~~~~   advisory details   ~~~~~~~~~~~~~~~~~~~ -->

<advisory from="secalert@redhat.com">

        <severity>Moderate</severity>

        <rights>Copyright 2009 Red Hat, Inc.</rights>
        <issued date="2009-06-15" />
        <updated date="2009-06-15" />
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-2541">CVE-2004-2541</cve>
            <cve href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0148">CVE-2009-0148</cve>
                <bugzilla href="http://bugzilla.redhat.com/490667" id="490667">CVE-2004-2541, CVE-2009-0148 cscope: multiple buffer overflows</bugzilla>
        <affected_cpe_list>
            <cpe>cpe:/o:redhat:enterprise_linux</cpe>
        </affected_cpe_list>
</advisory>
      </metadata>
      <criteria operator="AND">
 <criterion test_ref="oval:com.redhat.rhsa:tst:20090003001" comment="Red Hat Enterprise Linux 5 is installed" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091102002" comment="cscope is earlier than 0:15.5-15.1.el5_3.1" /><criterion test_ref="oval:com.redhat.rhsa:tst:20091102003" comment="cscope is signed with Red Hat redhatrelease key" />
  
</criteria>

    </definition>
<definition id="oval:com.redhat.rhsa:def:20091106" version="302" class="patch">
      <metadata>
        <title>RHSA-2009:1106: kernel security and bug fix update (Important)
    </title>
    <affected family="unix">
            <platform>Red Hat Enterprise Linux 5</platform>
             </affected>
        <reference source="RHSA" ref_id="RHSA-2009:1106-01" ref_url="https://rhn.redhat.com/errata/RHSA-2009-1106.html" />
    <description>The kernel packages contain the Linux kernel, the core of any Linux
operating system.

Security fixes:

* several flaws were found in the way the Linux kernel CIFS implementation
handles Unicode strings. CIFS clients convert Unicode strings sent by a
server to their local character sets, and then write those strings into
memory. If a malicious server sent a long enough string, it could write
past the end of the target memory region and corrupt other memory areas,
possibly leading to a denial of service or privilege escalation on the
client mounting the CIFS share. (CVE-2009-1439, CVE-2009-1633, Important)

* the Linux kernel Network File System daemon (nfsd) implementation did not
drop the CAP_MKNOD capability when handling requests from local,
unprivileged users. This flaw could possibly lead to an information leak or
privilege escalation. (CVE-2009-1072, Moderate)

* Frank Filz reported the NFSv4 client was missing a file permission check
for the execute bit in some situations. This could allow local,
unprivileged users to run non-executable files on NFSv4 mounted file
systems. (CVE-2009-1630, Moderate)

* a missing check was found in the hypervisor_callback() function in the
Linux kernel provided by the kernel-xen package. This could cause a denial
of service of a 32-bit guest if an application running in that guest
accesses a certain memory location in the kernel. (CVE-2009-1758, Moderate)

* a flaw was found in the AGPGART driver. The agp_generic_alloc_page() and
agp_generic_alloc_pages() functions did not zero out the memory pages they
allocate, which may later be available to user-space processes. This flaw
could possibly lead to an information leak. (CVE-2009-1192, Low)

Bug fixes:

* a race in the NFS client between destroying cached access rights and
unmounting an NFS file system could have caused a system crash. "Busy
inodes" messages may have been logged. (BZ#498653)

* nanosleep() could sleep several milliseconds less than the specified time
on Intel Itanium®-based systems. (BZ#500349)

* LEDs for disk drives in AHCI mode may have displayed a fault state when
there were no faults. (BZ#500120)

* ptrace_do_wait() reported tasks were stopped each time the process doing